Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
474 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.26% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (7.8) | 0.27% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Alta (7.8) | 0.26% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V10 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (7.8) | 0.26% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target must… | |
| Analizada | Alta (7.8) | 0.27% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Alta (7.8) | 0.27% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V8C File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Alta (7.8) | 0.29% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Alta (7.8) | 0.27% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Alta (7.8) | 0.27% | — | Fujielectric Monitouch V-sft | 28/11/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Monitouch V-SFT. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Crítica (9.8) | 0.45% | — | Wpwebelite Woocommerce PDF Vouchers | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouchers: from n/a through 4.9.4. | |
| Aplazada | Media (6.4) | 0.34% | — | Gift Cards Gift Vouchers AND PackagesAI | 31/10/2024 | 17/6/2026 | The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.6) | 0.30% | — | Aliyuncontainerservice PouchAI | 23/9/2024 | 17/6/2026 | A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files. | |
| Modificada | Media (6.1) | 0.30% | — | Couchbase Server | 19/9/2024 | 17/6/2026 | Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection. | |
| Analizada | Crítica (9.3) | 0.50% | — | Wpwebelite Woocommerce PDF Vouchers | 13/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5. | |
| Analizada | Media (6.1) | 0.31% | — | Wpwebelite Woocommerce PDF Vouchers | 1/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5. | |
| Modificada | Media (5.9) | 0.16% | — | Couchbase Server | 26/7/2024 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure. | |
| Aplazada | Alta (7.3) | 0.40% | — | Wpwebelite Woocommerce PDF VouchersAI | 24/7/2024 | 17/6/2026 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient verification on the user being supplied during a QR code login through the plugin. This makes it possible for unauthenticated attackers to log in as any… | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (8.5) | 0.51% | — | Fujielectric Monitouch V-sft | 10/6/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT is vulnerable to a type confusion, which could cause a crash or code execution. | |
| Aplazada | Alta (8) | 0.28% | — | Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI | 7/6/2024 | 17/6/2026 | Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges. | |
| Aplazada | Alta (8.8) | 0.32% | — | Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI | 7/6/2024 | 17/6/2026 | Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information. | |
| Aplazada | Alta (8.8) | 0.32% | — | Precor Touchscreen Console P82AI | 7/6/2024 | 17/6/2026 | Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges. | |
| Aplazada | Alta (7.8) | 0.20% | — | Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI | 7/6/2024 | 17/6/2026 | Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, because there is a hard-coded service code. | |
| Analizada | Alta (8.5) | 0.38% | — | Fujielectric Monitouch V-sft | 30/5/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result in arbitrary code execution. | |
| Analizada | Alta (8.5) | 0.56% | — | Fujielectric Monitouch V-sft | 30/5/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code. |