Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

439 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.22%—Primekey Ejbca31/3/202517/6/2026
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an external page. This vulnerability could allow users to be redirected to potentially malicious external…
AnalizadaMedia (5.1)0.23%—Primekey Ejbca31/3/202517/6/2026
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulate the generated links and thus redirect the client to a different base URL. In this way, an attacker could insert his own server for the…
AnalizadaCrítica (9.8)1.8%—Nasa Fprime25/3/202517/6/2026
A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.
AnalizadaMedia (6.1)0.29%—Nasa Fprime25/3/202517/6/2026
NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
AnalizadaCrítica (9.8)0.79%—Nasa Fprime25/3/202517/6/2026
A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.
AnalizadaMedia (4.3)0.29%—Metagauss Eventprime7/3/202517/6/2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.3)0.33%—Nilambar Prime Addons FOR Elementor20/2/202517/6/2026
The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and…
AplazadaMedia (5.4)0.19%—Intel Quartus PrimeAI12/2/202517/6/2026
Uncontrolled search path for some Intel(R) Quartus(R) Prime Software before version 23.1.1 Patch 1.01std may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.8)0.19%—Tally Prime Edit LOGAI7/2/202517/6/2026
Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL.
AnalizadaMedia (5.4)0.22%—Bdthemes Prime Slider23/1/202517/6/2026
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Post Slider and Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'social_link_title' parameter of the 'blog' widget in all versions up to, and including, 3.16.5 due to insufficient input…
ModificadaMedia (6.1)0.42%—Metagauss Eventprime17/12/202417/6/2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.7.3 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (6.1)0.30%—Primer MydataAI13/12/202417/6/2026
The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src' parameter in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AnalizadaMedia (6.3)0.43%—Cisco Prime Data Center Network Manager18/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. The vulnerability is due to a failure to limit access to resources that are intended for users with…
AnalizadaMedia (6.1)0.53%—Cisco Prime Collaboration Deployment15/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate…
AnalizadaMedia (6.1)0.51%—Cisco Prime InfrastructureCisco Evolved Programmable Network Manager15/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate…
AnalizadaMedia (6.5)1.7%—Cisco Prime InfrastructureCisco Evolved Programmable Network Manager15/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the system. This vulnerability is due to…
AnalizadaMedia (5.4)0.45%—Cisco Prime Access Registrar15/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco Prime Access Registrar Appliance could allow an authenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. The attacker would require valid credentials for the device. This vulnerability is due to…
AnalizadaMedia (5.4)0.16%—Intel Quartus Prime13/11/202417/6/2026
Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.16%—Intel Quartus Prime13/11/202417/6/2026
Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.18%—Intel High Level Synthesis CompilerAIIntel Quartus Prime PRO EditionAI13/11/202417/6/2026
Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software for Intel(R) Quartus(R) Prime Pro Edition Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.33%—Bdthemes Prime Slider7/11/202417/6/2026
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on user supplied…
AnalizadaMedia (5.4)0.28%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure6/11/202417/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists…
AnalizadaAlta (8.8)0.40%—Metagauss Eventprime1/11/202417/6/2026
Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 4.0.3.2.
AnalizadaMedia (6.1)0.39%—Metagauss Eventprime24/10/202417/6/2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AnalizadaMedia (6.1)0.32%—Metagauss Eventprime24/10/202417/6/2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
Orbitaley — Vulnerabilidades