Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.26%—Jtekt Screen Creator Advance 213/2/202317/6/2026
Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process when out of specification errors are detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary…
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+14330/1/202317/6/2026
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+13230/1/202317/6/2026
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+32130/1/202317/6/2026
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaMedia (6.7)0.26%—Lenovo D330-10igl FirmwareLenovo Ideapad 5 PRO 16iah7 FirmwareLenovo Ideapad 5 PRO 16arh7 FirmwareLenovo Ideapad Duet 3 10igl5 Firmware+4023/1/202317/6/2026
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
ModificadaMedia (4.8)0.47%—Cozmoslabs Custom Post Types AND Custom Fields Creator16/1/202317/6/2026
The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
ModificadaMedia (6.7)0.45%—Corel Roxio Creator LJB21/12/202217/6/2026
Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service. The affected product and versions are as…
ModificadaAlta (8.8)0.61%—Bulk Page Creator Project Bulk Page Creator30/5/202217/6/2026
The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF.
ModificadaAlta (7)0.22%—Koyoele Remote GCKoyoele Screen Creator Advance 2Koyoele Gc-a22w-cw FirmwareKoyoele Gc-a24 Firmware+618/5/202217/6/2026
Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, GC-A26, and GC-A26-J2), and Real time remote monitoring and control tool(Remote…
ModificadaMedia (6.7)0.26%—Lenovo C340-14iml FirmwareLenovo C340-15iml FirmwareLenovo D330-10igm FirmwareLenovo Duet 3-10igl5 Firmware+5822/4/202217/6/2026
A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)0.26%—Lenovo A340-22icb FirmwareLenovo A340-22ick FirmwareLenovo A340-24icb FirmwareLenovo A340-24ick Firmware+4922/4/202217/6/2026
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (6.7)2.8%💥 PoCLenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+10122/4/202217/6/2026
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
ModificadaMedia (6.7)1.2%—Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+6922/4/202217/6/2026
A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable.
ModificadaMedia (6.7)1.3%—Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+10122/4/202217/6/2026
A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (5.3)5.7%💥 PoCVmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Cloud Secure AgentNetapp Metrocluster Tiebreaker+314/4/202217/6/2026
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and…
ModificadaMedia (6.1)0.80%—Bulk Creator Project Bulk Creator28/3/202217/6/2026
The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
ModificadaAlta (7.5)4.9%💥 PoCFasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+3211/3/202217/6/2026
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
ModificadaCrítica (9.8)3.9%—Printable Staff ID Card Creator System Project Printable Staff ID Card Creator System12/1/202217/6/2026
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
ModificadaMedia (6.6)4.4%—QOS LogbackRedhat SatelliteNetapp Cloud ManagerNetapp Service Level Manager+216/12/202117/6/2026
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
ModificadaMedia (6.8)0.24%—Lenovo Ideacentre C5-14mb05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5-14imb05 FirmwareLenovo Ideacentre 5-14iob6 Firmware+5512/11/202117/6/2026
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
ModificadaMedia (4.8)0.62%—Bookingholdings Booking.com Banner Creator8/11/202117/6/2026
The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (4.3)1.4%—Vmware Spring FrameworkNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Metrocluster Tiebreaker+428/10/202117/6/2026
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
ModificadaMedia (5.3)99%💥 ExploitEclipse JettyNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB ServicesNetapp Element Plug-in FOR Vcenter Server+1415/7/202117/6/2026
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
ModificadaBaja (3.5)0.96%💥 PoCEclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+1222/6/202117/6/2026
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated.…
ModificadaMedia (5.3)78%💥 ExploitEclipse JettyDebian LinuxOracle Communications Cloud Native Core PolicyOracle Rest Data Services+49/6/202117/6/2026
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive…