Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Brandsdistribution Bdroppy | 24/4/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component. | |
| Modificada | Alta (8.8) | 0.66% | — | Brandbugle | 7/6/2022 | 17/6/2026 | A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is some unknown functionality of the file /main.php. The manipulation leads to sql injection. The attack may be launched remotely. | |
| Modificada | Alta (8.1) | 83% | 💥 Exploit | Brandexponents Tatsu | 25/4/2022 | 17/6/2026 | The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.… | |
| Modificada | Alta (7.5) | 1.2% | — | Quadlayers Perfect Brands FOR Woocommerce | 18/2/2022 | 17/6/2026 | The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure. | |
| Modificada | Media (4.3) | 0.63% | — | Quadlayers Perfect Brands FOR Woocommerce | 18/2/2022 | 17/6/2026 | The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4). | |
| Modificada | Crítica (9.8) | 1.4% | — | Brandy Project Brandy | 11/10/2021 | 17/6/2026 | A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function. | |
| Modificada | Alta (8.6) | 1.1% | — | Acuitybrands Nlight Eclypse System Controller Firmware | 17/9/2021 | 17/6/2026 | nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controllers utilize an encrypted channel to secure SensorViewTM configuration and… | |
| Modificada | Media (5.4) | 0.62% | — | Thememason Popular Brand Icons - Simple Icons | 2/8/2021 | 17/6/2026 | The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an… | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Brand Verification Tool | 17/6/2021 | 17/6/2026 | Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.35% | — | Intel Brand Verification ToolFedoraproject FedoraIntel Pentium Processors FirmwareIntel Celeron Processors Firmware+3 | 9/6/2021 | 17/6/2026 | Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Media (5.5) | 0.84% | — | Brandy Project Brandy | 5/8/2019 | 17/6/2026 | Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code. | |
| Modificada | Media (5.5) | 0.84% | — | Brandy Project Brandy | 5/8/2019 | 17/6/2026 | Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code. | |
| Modificada | Media (5.5) | 0.84% | — | Brandy Project Brandy | 5/8/2019 | 17/6/2026 | Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code. | |
| Modificada | Crítica (9.8) | 4.0% | 💥 Exploit | Themashabrand Online Voting Platform | 8/2/2018 | 17/6/2026 | A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts. | |
| Modificada | Media (5.4) | 0.27% | — | Aventinobrand Aventino Brand | 19/10/2014 | 17/6/2026 | The Aventino Brand (aka com.AventinoBrand) application 2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 3.0% | — | Brandon Long Clearsilver | 10/12/2011 | 16/6/2026 | Format string vulnerability in the p_cgi_error function in python/neo_cgi.c in the Python CGI Kit (neo_cgi) module for Clearsilver 0.10.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are not properly handled when creating… | |
| Modificada | Media (4.6) | 0.46% | — | Debian LinuxRedhat FedoraUbuntu LinuxBranden Robinson Xvfb-run | 6/5/2009 | 16/6/2026 | xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Marcello Brandao Yogurt Social Network Module | 13/8/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Brandon Tallent Phptest | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Brand039 Mmslamp | 28/12/2007 | 16/6/2026 | SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the idpro parameter in a prodotti_dettaglio action. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Michael Brandon Vbgsitemap | 31/5/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2) vbgsitemap/vbgsitemap-vbseo.php. | |
| Modificada | Media (4.6) | 0.56% | 💥 Exploit | Rebrand P2P Share SPY | 2/5/2005 | 16/6/2026 | Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges. |