Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.2%—Brandsdistribution Bdroppy24/4/202317/6/2026
SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.
ModificadaAlta (8.8)0.66%—Brandbugle7/6/202217/6/2026
A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is some unknown functionality of the file /main.php. The manipulation leads to sql injection. The attack may be launched remotely.
ModificadaAlta (8.1)83%💥 ExploitBrandexponents Tatsu25/4/202217/6/2026
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.…
ModificadaAlta (7.5)1.2%—Quadlayers Perfect Brands FOR Woocommerce18/2/202217/6/2026
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.
ModificadaMedia (4.3)0.63%—Quadlayers Perfect Brands FOR Woocommerce18/2/202217/6/2026
The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4).
ModificadaCrítica (9.8)1.4%—Brandy Project Brandy11/10/202117/6/2026
A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.
ModificadaAlta (8.6)1.1%—Acuitybrands Nlight Eclypse System Controller Firmware17/9/202117/6/2026
nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controllers utilize an encrypted channel to secure SensorViewTM configuration and…
ModificadaMedia (5.4)0.62%—Thememason Popular Brand Icons - Simple Icons2/8/202117/6/2026
The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an…
ModificadaAlta (7.8)0.21%—Intel Brand Verification Tool17/6/202117/6/2026
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.35%—Intel Brand Verification ToolFedoraproject FedoraIntel Pentium Processors FirmwareIntel Celeron Processors Firmware+39/6/202117/6/2026
Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (5.5)0.84%—Brandy Project Brandy5/8/201917/6/2026
Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code.
ModificadaMedia (5.5)0.84%—Brandy Project Brandy5/8/201917/6/2026
Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code.
ModificadaMedia (5.5)0.84%—Brandy Project Brandy5/8/201917/6/2026
Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code.
ModificadaCrítica (9.8)4.0%💥 ExploitThemashabrand Online Voting Platform8/2/201817/6/2026
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts.
ModificadaMedia (5.4)0.27%—Aventinobrand Aventino Brand19/10/201417/6/2026
The Aventino Brand (aka com.AventinoBrand) application 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)3.0%—Brandon Long Clearsilver10/12/201116/6/2026
Format string vulnerability in the p_cgi_error function in python/neo_cgi.c in the Python CGI Kit (neo_cgi) module for Clearsilver 0.10.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are not properly handled when creating…
ModificadaMedia (4.6)0.46%—Debian LinuxRedhat FedoraUbuntu LinuxBranden Robinson Xvfb-run6/5/200916/6/2026
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
ModificadaMedia (4.3)1.5%💥 ExploitMarcello Brandao Yogurt Social Network Module13/8/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description…
ModificadaAlta (7.5)0.97%💥 ExploitBrandon Tallent Phptest30/7/200816/6/2026
SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitBrand039 Mmslamp28/12/200716/6/2026
SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the idpro parameter in a prodotti_dettaglio action.
ModificadaAlta (7.5)7.0%💥 ExploitMichael Brandon Vbgsitemap31/5/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2) vbgsitemap/vbgsitemap-vbseo.php.
ModificadaMedia (4.6)0.56%💥 ExploitRebrand P2P Share SPY2/5/200516/6/2026
Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges.
Orbitaley — Vulnerabilidades