Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)1.3%—HP Pagewide PRO 577z K9z76a FirmwareHP Pagewide PRO 577z K9z76b FirmwareHP Pagewide PRO 577z K9z76d FirmwareHP Pagewide PRO 577dw D3q21a Firmware+409/11/202117/6/2026
A Buffer Overflow and Information Disclosure issue exists in HP OfficeJet Pro Printers before 001.1937C, and HP PageWide Managed Printers and HP PageWide Pro Printers before 001.1937D exists; A maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer…
ModificadaAlta (7.8)0.38%—HP Officejet 4650 E6g87a FirmwareHP Officejet 4650 F1h96a FirmwareHP Officejet 4650 F1h96b FirmwareHP Officejet 4650 F1j03a Firmware+1513/11/202117/6/2026
HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.
ModificadaMedia (4.8)0.62%—Yoohooplugins Sitewide Notice30/8/202117/6/2026
The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaBaja (3.3)0.83%—Nasm Netwide Assembler25/8/202117/6/2026
Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.
ModificadaCrítica (9.8)3.7%—Idemia Morphowave Compact Mdpi FirmwareIdemia Morphowave Compact Mdpi-m FirmwareIdemia Visionpass Mdpi FirmwareIdemia Visionpass Mdpi-m Firmware+722/7/202117/6/2026
A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via TCP/IP packets.
ModificadaMedia (5.5)0.24%—Cisco Wide Area Application Services6/5/202117/6/2026
A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An…
ModificadaMedia (5.5)0.19%—LG IpsfullhdLG UltrawideLgpcsuite SetupLG Ultra HD Driver Setup14/9/202017/6/2026
A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in ____COMPONENT____ of LG Electronics (LGPCSuite_Setup), (IPSFULLHD,…
ModificadaCrítica (9.8)1.4%—Nasm Netwide Assembler4/9/202017/6/2026
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
ModificadaMedia (5.5)0.74%—Nasm Netwide Assembler25/8/202017/6/2026
In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.
ModificadaMedia (5.5)0.78%—Nasm Netwide Assembler25/8/202017/6/2026
In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.
ModificadaAlta (7.1)0.84%—Nasm Netwide Assembler6/1/202017/6/2026
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c.
ModificadaMedia (5.5)0.76%—Nasm Netwide Assembler4/1/202017/6/2026
In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (and stdscan in asm/stdscan.c). This is similar to CVE-2019-6290 and CVE-2019-6291.
ModificadaMedia (5.5)0.92%—Nasm Netwide Assembler24/7/201917/6/2026
In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list, and nasm_set_limit when "%pragma limit" is mishandled.
ModificadaAlta (7.5)2.6%—B3log Wide18/7/201917/6/2026
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the attacker can create a symlink, and then place the symlink into a ZIP archive. An unzip operation…
ModificadaMedia (5.3)1.8%—Cisco Wide Area Application Services20/6/201917/6/2026
A vulnerability in the HTTPS proxy feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to use the Central Manager as an HTTPS proxy. The vulnerability is due to insufficient authentication of proxy connection requests. An attacker could exploit this…
ModificadaCrítica (9.8)2.6%—HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Cp5525 FirmwareHP Color Laserjet Enterprise M553 FirmwareHP Color Laserjet Enterprise M552 Firmware+13911/4/201917/6/2026
HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code.
ModificadaCrítica (9.8)2.6%—HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Cp5525 FirmwareHP Color Laserjet Enterprise Flow MFP M681f FirmwareHP Color Laserjet Enterprise Flow MFP M681z Firmware+13427/3/201917/6/2026
In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.
ModificadaAlta (7.8)1.1%—Nasm Netwide Assembler15/2/201917/6/2026
In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
ModificadaMedia (5.5)0.75%—Nasm Netwide Assembler29/1/201917/6/2026
A buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted asm input can cause segmentation faults, leading to denial-of-service.
ModificadaMedia (5.5)1.3%—Nasm Netwide Assembler15/1/201917/6/2026
An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem caused by the expr6 function making recursive calls to itself in certain scenarios involving lots of '!' or '+' or '-' characters. Remote attackers could leverage this vulnerability…
ModificadaMedia (5.5)1.3%—Nasm Netwide Assembler15/1/201917/6/2026
An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote attackers could leverage this vulnerability…
ModificadaMedia (5.5)0.79%—Nasm Netwide Assembler28/12/201817/6/2026
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests.
ModificadaMedia (5.5)0.80%—Nasm Netwide Assembler28/12/201817/6/2026
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt.
ModificadaMedia (5.5)0.75%—Nasm Netwide Assembler20/12/201817/6/2026
nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-overflow caused by triggering endless macro generation, crash the program. This attack appear to be exploitable via a crafted nasm input file.
ModificadaMedia (5.5)1.00%—Nasm Netwide Assembler30/11/201817/6/2026
There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.
Orbitaley — Vulnerabilidades