Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+953 | 14/6/2023 | 17/6/2026 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. | |
| Modificada | Media (5.3) | 0.32% | — | Jenkins Neuvector Vulnerability Scanner | 12/4/2023 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server. | |
| Modificada | Media (6.5) | 0.64% | — | Gitlab Dast API Scanner | 1/2/2023 | 17/6/2026 | A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report | |
| Modificada | Media (5.3) | 0.70% | — | Jenkins Neuvector Vulnerability Scanner | 19/10/2022 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download. | |
| Modificada | Media (5.4) | 0.72% | — | Jenkins Anchore Container Image Scanner | 21/9/2022 | 17/6/2026 | Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine. | |
| Modificada | Alta (7.5) | 1.3% | — | Pyramidsolutions Netstax Ethernet/ip Adapter Development KITPyramidsolutions Netstax Ethernet/ip Adapter DLL KITPyramidsolutions Netstax Ethernet/ip Scanner Development KITPyramidsolutions Netstax Ethernet/ip Scanner DLL KIT | 12/7/2022 | 17/6/2026 | Pyramid Solutions' affected products, the Developer and DLL kits for EtherNet/IP Adapter and EtherNet/IP Scanner, are vulnerable to an out-of-bounds write, which may allow an unauthorized attacker to send a specially crafted packet that may result in a denial-of-service condition. | |
| Modificada | Media (4.8) | 0.58% | — | Miniorange Malware Scanner | 27/6/2022 | 17/6/2026 | The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Ml-scanner | 24/6/2022 | 17/6/2026 | The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Emcosoftware MSI Package BuilderEmcosoftware Network InventoryEmcosoftware Network Software ScannerEmcosoftware Ping Monitor+4 | 23/5/2022 | 9/7/2026 | Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows… | |
| Modificada | Alta (7.5) | 1.5% | — | Weka Interest Security Scanner | 28/3/2022 | 17/6/2026 | A vulnerability has been found in WEKA INTEREST Security Scanner up to 1.8 and classified as problematic. This vulnerability affects unknown code of the component Portscan. The manipulation with an unknown input leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.5) | 0.26% | — | Weka Interest Security Scanner | 28/3/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in WEKA INTEREST Security Scanner up to 1.8. This affects an unknown part of the component LAN Viewer. The manipulation with an unknown input leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.5) | 0.26% | — | Weka Interest Security Scanner | 28/3/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in WEKA INTEREST Security Scanner up to 1.8. Affected by this issue is some unknown functionality of the component Webspider. The manipulation with an unknown input leads to denial of service. Local access is required to approach this attack. The… | |
| Modificada | Media (5.5) | 0.29% | — | Weka Interest Security Scanner | 28/3/2022 | 17/6/2026 | A vulnerability classified as problematic was found in WEKA INTEREST Security Scanner up to 1.8. Affected by this vulnerability is the Stresstest Configuration Handler. A manipulation leads to a local denial of service. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects… | |
| Modificada | Media (5.5) | 0.30% | — | Weka Interest Security Scanner | 28/3/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in WEKA INTEREST Security Scanner up to 1.8. Affected is Stresstest Scheme Handler which leads to a denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects… | |
| Modificada | Media (5.5) | 0.23% | — | Weka Interest Security Scanner | 28/3/2022 | 17/6/2026 | A vulnerability was found in WEKA INTEREST Security Scanner 1.8. It has been rated as problematic. This issue affects some unknown processing of the component HTTP Handler. The manipulation with an unknown input leads to denial of service. It is possible to launch the attack on the local host. The exploit has been… | |
| Modificada | Alta (7.8) | 0.25% | — | Snowsoftware Snow Inventory Java Scanner | 16/2/2022 | 17/6/2026 | A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0 | |
| Modificada | Media (5.3) | 1.6% | — | S3scanner Project S3scanner | 29/11/2021 | 17/6/2026 | S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a ListBucketResult element. | |
| Modificada | Media (6.1) | 0.60% | — | Tidesec Wdscanner | 30/7/2021 | 17/6/2026 | Cross Site Scripting vulnerabiity exists in WDScanner 1.1 in the system management page. | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 3.1% | 💥 Exploit | Documalis Free PDF EditorDocumalis Free PDF Scanner | 12/8/2020 | 17/6/2026 | Documalis Free PDF Editor version 5.7.2.26 and Documalis Free PDF Scanner version 5.7.2.122 do not appropriately validate the contents of JPEG images contained within a PDF. Attackers can exploit this vulnerability to trigger a buffer overflow on the stack and gain remote code execution as the user running the… | |
| Modificada | Crítica (9.8) | 2.5% | — | Thingssdk Wifiscanner | 29/6/2020 | 17/6/2026 | wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code. | |
| Modificada | Alta (7.1) | 0.40% | — | Openvas-scanner | 25/11/2019 | 16/6/2026 | openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system. | |
| Modificada | Media (6.5) | 0.85% | — | Jenkins Anchore Container Image Scanner | 21/11/2019 | 17/6/2026 | Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (5.5) | 0.17% | — | Mailscanner | 12/11/2019 | 16/6/2026 | The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing. | |
| Modificada | Media (4.7) | 0.34% | — | Mailscanner | 12/11/2019 | 16/6/2026 | mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313. |