Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.87% | — | Microchip Mplab Network Creator | 10/10/2023 | 17/6/2026 | In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random. | |
| Modificada | Alta (7.8) | 0.21% | — | Lenovo Ideapad Creator 5-16ach6 FirmwareLenovo Ideapad 5 Pro-16ihu6 FirmwareLenovo Ideapad 5 Pro-16ach6 FirmwareLenovo Yoga Slim 7-13itl05 Firmware+21 | 9/10/2023 | 17/6/2026 | A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |
| Modificada | Crítica (9.8) | 0.74% | — | Presto-changeo Test Site Creator | 5/10/2023 | 17/6/2026 | Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php. | |
| Modificada | Crítica (9.8) | 0.63% | — | Presto-changeo Testsitecreator | 2/10/2023 | 17/6/2026 | Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Document Creator | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Media (6.7) | 0.17% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface. | |
| Modificada | Media (4.4) | 0.18% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI. | |
| Modificada | Media (6.7) | 0.17% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential. | |
| Modificada | Media (4.4) | 0.18% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Document Creator | 10/8/2023 | 17/6/2026 | PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed". | |
| Modificada | Crítica (9.8) | 0.79% | — | Phpjabbers Document Creator | 10/8/2023 | 17/6/2026 | There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Document Creator | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Document Creator | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0. | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3 07ach7 FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07ada05 Firmware+110 | 5/6/2023 | 17/6/2026 | An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code. | |
| Modificada | Media (5.4) | 0.55% | — | Teclib-edition Form Creator | 31/5/2023 | 17/6/2026 | Formcreator is a GLPI plugin which allow creation of custom forms and the creation of one or more tickets when the form is filled. A probable stored cross-site scripting vulnerability is present in Formcreator 2.13.5 and prior via the use of the use of `##FULLFORM##` for rendering. This could result in arbitrary… | |
| Modificada | Alta (7.8) | 0.22% | — | Jtekt Screen Creator Advance 2 | 11/4/2023 | 17/6/2026 | Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a project file. If a user of Screen Creator Advance 2 opens a specially crafted project file, information… | |
| Modificada | Alta (7.8) | 0.43% | — | Wondershare Democreator | 4/4/2023 | 17/6/2026 | An issue found in Wondershare Technology Co., Ltd DemoCreator v.6.0.0 allows a remote attacker to execute arbitrary commands via the democreator_setup_full7743.exe file. | |
| Modificada | Alta (7.8) | 0.89% | — | Jtekt Screen Creator Advance 2 | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of KOYO Screen Creator 0.1.1.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SCA2 files.… | |
| Modificada | Alta (7.8) | 0.29% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.31% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing control management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or… | |
| Modificada | Alta (7.8) | 0.31% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing parts management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or… | |
| Modificada | Alta (7.8) | 0.33% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing screen management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or… | |
| Modificada | Alta (7.8) | 0.33% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing file structure information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or… | |
| Modificada | Alta (7.8) | 0.33% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing template information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code… |