Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1025 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.08%—Intel Wheaerst SMM ModuleAI10/3/202617/6/2026
Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access…
Pendiente de análisisAlta (7.1)0.10%—Intel Uefi Wheaerst ModuleAI10/3/202617/6/2026
Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack…
AnalizadaMedia (5.1)0.14%—Vivo Health Module27/2/202617/6/2026
Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.
AnalizadaAlta (7.1)0.26%—Vivo Smartremote Module27/2/202617/6/2026
The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
AplazadaAlta (7.8)0.10%—Dell Idrac Service ModuleAIDell Idrac Service Module FOR WindowsAIDell Idrac Service Module FOR LinuxAI12/2/202617/6/2026
Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of…
AplazadaMedia (5.6)0.10%—Intel TDX ModuleAI10/2/202617/6/2026
Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements…
AplazadaMedia (5.6)0.12%—Intel TDX ModuleAI10/2/202617/6/2026
Out-of-bounds read for some TDX before version tdx module 1.5.24 within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are…
AplazadaMedia (5.6)0.08%—Intel TDX ModuleAI10/2/202617/6/2026
Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present…
AplazadaAlta (8.3)0.13%—Intel TDX ModuleAI10/2/202617/6/2026
Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with…
AplazadaMedia (5.6)0.10%—Intel TDX ModuleAI10/2/202617/6/2026
Out-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Software side channel adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements…
AplazadaMedia (5.7)0.14%—Intel TDX ModuleAI10/2/202617/6/2026
Improper buffer restrictions in the firmware for the TDX Module may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present…
AnalizadaAlta (7.8)0.13%—Tanium Module ServerTanium Server9/2/202617/6/2026
Tanium addressed a local privilege escalation vulnerability in Tanium Server.
AnalizadaAlta (7.8)0.13%—Tanium Module ServerTanium Server9/2/202617/6/2026
Tanium addressed a local privilege escalation vulnerability in Tanium Module Server.
AplazadaCrítica (9.8)0.44%—Xpoda Turkiye Information Technology INC Password ModuleAI9/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection. This issue affects Password Module: through 11022026.
AnalizadaAlta (7.8)0.35%—Node-modules Compressing4/2/202617/6/2026
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks that resolve outside the intended extraction directory, an attacker can cause subsequent file…
AplazadaMedia (6)0.58%—Python Email ModuleAI23/1/202617/6/2026
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new…
AplazadaAlta (8.7)0.57%—Graphql ModulesAI16/1/202617/6/2026
GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the context of the requests is mixed up in the…
AplazadaAlta (8.8)0.57%—Supreme Modules LiteAI15/1/202617/6/2026
The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it…
AnalizadaMedia (4.8)0.20%—Flag Module Project Flag14/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag allows Cross-Site Scripting (XSS).This issue affects Flag: from 7.X-3.0 through 7.X-3.9.
AplazadaAlta (8.2)0.43%—Typo3 ModulesAI12/11/202517/6/2026
Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0 before 5.7.4, from 6.0.0 before 6.4.2, from 7.0.0 before 7.5.5.
AplazadaMedia (5.3)0.42%—Mitsubishi Electric Corporation Melsec Iq-f Series CPU ModuleAI6/11/202517/6/2026
Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote attacker to disconnect the connection by sending specially crafted TCP packets to cause a denial-of-service (DoS) condition on the products.…
AplazadaCrítica (9.3)0.49%—Galaxy Software Services Corporation Vitals ESP Forum ModuleAI20/10/202530/9/2026
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.
AnalizadaMedia (5.3)0.25%—Synchronize Composer.json With Contrib Modules Project Synchronize Composer.json With Contrib Modules10/10/202530/9/2026
Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*.
AplazadaAlta (7.3)0.46%—Mitsubishi Electric Corporation Melsec Iq-f Series CPU ModuleAI1/9/202517/6/2026
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not have authentication…
AnalizadaAlta (7.8)0.15%—Dell EMC Idrac Service Module21/8/202517/6/2026
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.