Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.2% | — | GNU GlibcDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+8 | 6/5/2024 | 17/6/2026 | nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only… | |
| Modificada | Alta (8.1) | 1.3% | — | GNU GlibcDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 6/5/2024 | 17/6/2026 | nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This… | |
| Aplazada | Media (4.3) | 0.20% | — | 5280 Bootstrap Modal Contact FormAI | 2/5/2024 | 17/6/2026 | The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in class-sbmm-list-table.php. This makes it possible for unauthenticated attackers to bulk delete messages via a forged… | |
| Modificada | Media (5.4) | 0.32% | — | Bootstrapped WP Recipe Maker | 2/5/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-roundup-item shortcode in all versions up to, and including, 9.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Crítica (9.8) | 1.7% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 24/8/2026 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component. | |
| Analizada | Crítica (9.8) | 1.9% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 17/6/2026 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component. | |
| Analizada | Alta (8) | 1.1% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component. | |
| Analizada | Crítica (9.8) | 1.9% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 17/6/2026 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component. | |
| Analizada | Alta (8.6) | 0.63% | — | Greenwoodsoftware LessDebian LinuxNetapp Bootstrap OSNetapp HCI Storage Nodes+1 | 13/4/2024 | 17/6/2026 | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment… | |
| Modificada | Alta (7) | 1.9% | — | EventletDnspythonFedoraproject FedoraNetapp Bootstrap OS | 11/4/2024 | 17/6/2026 | eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name… | |
| Modificada | Media (4.8) | 0.42% | — | Bootstrapped WP Recipe Maker | 9/4/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the recipe dashboard (which is… | |
| Modificada | Media (5.4) | 0.32% | — | G5plus Ultimate Bootstrap Elements FOR Elementor | 6/4/2024 | 17/6/2026 | The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Widget in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Analizada | Media (6.7) | 0.38% | — | GNU Grub2Netapp Bootstrap OS | 5/4/2024 | 17/6/2026 | GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass. | |
| Analizada | Media (6.5) | 1.3% | — | Haxx CurlApple MacosNetapp H700s FirmwareNetapp Bootstrap OS+3 | 27/3/2024 | 17/6/2026 | libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all… | |
| Analizada | Alta (8.6) | 36% | — | Haxx CurlApple MacosFedoraproject FedoraNetapp Active IQ Unified Manager+10 | 27/3/2024 | 17/6/2026 | When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.… | |
| Analizada | Media (6.3) | 1.7% | — | Haxx CurlApple MacosNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+8 | 27/3/2024 | 17/6/2026 | libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems. | |
| Analizada | Baja (3.5) | 1.7% | — | Haxx CurlFedoraproject FedoraApple MacosNetapp Ontap+6 | 27/3/2024 | 17/6/2026 | When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled.… | |
| Modificada | Media (6.4) | 0.51% | — | G5plus Ultimate Bootstrap Elements FOR Elementor | 2/3/2024 | 17/6/2026 | The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_title_tag’ and ’heading_sub_title_tag’ parameters in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.73% | — | Bootstrapped WP Recipe Maker | 29/2/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (7.5) | 74% | — | Netapp HCI Baseboard Management ControllerNetapp Active IQ Unified ManagerNetapp Bootstrap OSPowerdns Recursor+4 | 14/2/2024 | 17/6/2026 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an… | |
| Analizada | Media (4.9) | 0.69% | — | Intel Server Platform ServicesNetapp HCI Bootstrap OSNetapp HCI Compute Node Bios | 14/2/2024 | 17/6/2026 | Uncontrolled resource consumption for some Intel(R) SPS firmware before version SPS_E5_06.01.04.002.0 may allow a privileged user to potentially enable denial of service via network access. | |
| Modificada | Media (5.4) | 0.56% | — | Bootstrapped WP Recipe Maker | 5/2/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject… | |
| Modificada | Media (5.4) | 0.56% | — | Bootstrapped WP Recipe Maker | 5/2/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to unrestricted use of the 'header_tag' attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to… | |
| Modificada | Media (4.3) | 0.80% | — | Bootstrapped WP Recipe Maker | 5/2/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 9.1.0 via the 'icon' attribute used in Shortcodes. This makes it possible for authenticated attackers, with contributor-level access and above, to include the contents of SVG files on the server, which… | |
| Modificada | Media (5.4) | 0.52% | — | Bootstrapped WP Recipe Maker | 5/2/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… |