Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.26% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process when out of specification errors are detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary… | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+143 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+132 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+321 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo D330-10igl FirmwareLenovo Ideapad 5 PRO 16iah7 FirmwareLenovo Ideapad 5 PRO 16arh7 FirmwareLenovo Ideapad Duet 3 10igl5 Firmware+40 | 23/1/2023 | 17/6/2026 | A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |
| Modificada | Media (4.8) | 0.47% | — | Cozmoslabs Custom Post Types AND Custom Fields Creator | 16/1/2023 | 17/6/2026 | The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Media (6.7) | 0.45% | — | Corel Roxio Creator LJB | 21/12/2022 | 17/6/2026 | Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service. The affected product and versions are as… | |
| Modificada | Alta (8.8) | 0.61% | — | Bulk Page Creator Project Bulk Page Creator | 30/5/2022 | 17/6/2026 | The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF. | |
| Modificada | Alta (7) | 0.22% | — | Koyoele Remote GCKoyoele Screen Creator Advance 2Koyoele Gc-a22w-cw FirmwareKoyoele Gc-a24 Firmware+6 | 18/5/2022 | 17/6/2026 | Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, GC-A26, and GC-A26-J2), and Real time remote monitoring and control tool(Remote… | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo C340-14iml FirmwareLenovo C340-15iml FirmwareLenovo D330-10igm FirmwareLenovo Duet 3-10igl5 Firmware+58 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo A340-22icb FirmwareLenovo A340-22ick FirmwareLenovo A340-24icb FirmwareLenovo A340-24ick Firmware+49 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 2.8% | 💥 PoC | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+101 | 22/4/2022 | 17/6/2026 | A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 1.2% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+69 | 22/4/2022 | 17/6/2026 | A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 1.3% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+101 | 22/4/2022 | 17/6/2026 | A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (5.3) | 5.7% | 💥 PoC | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Cloud Secure AgentNetapp Metrocluster Tiebreaker+3 | 14/4/2022 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and… | |
| Modificada | Media (6.1) | 0.80% | — | Bulk Creator Project Bulk Creator | 28/3/2022 | 17/6/2026 | The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+32 | 11/3/2022 | 17/6/2026 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | |
| Modificada | Crítica (9.8) | 3.9% | — | Printable Staff ID Card Creator System Project Printable Staff ID Card Creator System | 12/1/2022 | 17/6/2026 | In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution. | |
| Modificada | Media (6.6) | 4.4% | — | QOS LogbackRedhat SatelliteNetapp Cloud ManagerNetapp Service Level Manager+2 | 16/12/2021 | 17/6/2026 | In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. | |
| Modificada | Media (6.8) | 0.24% | — | Lenovo Ideacentre C5-14mb05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5-14imb05 FirmwareLenovo Ideacentre 5-14iob6 Firmware+55 | 12/11/2021 | 17/6/2026 | A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes. | |
| Modificada | Media (4.8) | 0.62% | — | Bookingholdings Booking.com Banner Creator | 8/11/2021 | 17/6/2026 | The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.3) | 1.4% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Metrocluster Tiebreaker+4 | 28/10/2021 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. | |
| Modificada | Media (5.3) | 99% | 💥 Exploit | Eclipse JettyNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB ServicesNetapp Element Plug-in FOR Vcenter Server+14 | 15/7/2021 | 17/6/2026 | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5. | |
| Modificada | Baja (3.5) | 0.96% | 💥 PoC | Eclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+12 | 22/6/2021 | 17/6/2026 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated.… | |
| Modificada | Media (5.3) | 78% | 💥 Exploit | Eclipse JettyDebian LinuxOracle Communications Cloud Native Core PolicyOracle Rest Data Services+4 | 9/6/2021 | 17/6/2026 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive… |