Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

1895 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.6)0.86%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages.
ModificadaMedia (6.5)0.49%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values.
ModificadaMedia (5.4)0.68%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+819/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete.
ModificadaMedia (5.4)0.64%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+519/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing.
ModificadaAlta (7.5)0.77%—Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+1019/12/202217/6/2026
The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.
ModificadaAlta (7.5)0.89%—Kodcloud Kodexplorer6/12/202217/6/2026
Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed by arbitrary users. This issue has been…
ModificadaMedia (6.5)3.2%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer23/11/202217/6/2026
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
ModificadaMedia (4.9)3.7%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer23/11/202217/6/2026
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
ModificadaMedia (5.3)0.56%—Jenkins S3 Explorer19/10/202217/6/2026
Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.
ModificadaCrítica (9.8)1.7%—10-strike Network Inventory Explorer23/9/202217/6/2026
10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
ModificadaAlta (7.5)6.2%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer12/7/202217/6/2026
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)
ModificadaAlta (7.8)0.29%—Naver Cloud Explorer13/6/202217/6/2026
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaAlta (7.8)0.46%—Systemexplorer System Explorer4/4/202217/6/2026
An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.
ModificadaMedia (4.3)1.6%—Microsoft Azure Data Explorer9/2/202217/6/2026
Azure Data Explorer Spoofing Vulnerability
ModificadaAlta (7.8)0.81%—Opendesign Drawings Explorer21/12/202117/6/2026
An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer before 2022.12. The specific issue exists after loading BMP files. Unchecked input data from a crafted BMP file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute…
ModificadaAlta (7.8)0.84%—Opendesign Drawings Explorer5/12/202117/6/2026
An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer before 2022.11. The specific issue exists after loading TIF files. Crafted data in a TIF file can trigger a write operation past the end of an allocated buffer. An attacker can leverage this…
ModificadaMedia (4.6)0.42%—File Explorer Project File Explorer22/10/202117/6/2026
An issue in the authentication mechanism in Nong Ge File Explorer v1.4 unauthenticated allows to access sensitive data.
ModificadaMedia (6.5)0.56%—Netexplorer MY Smtp Contact10/8/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
ModificadaCrítica (9.8)7.4%—Zohocorp Manageengine Assetexplorer19/7/202117/6/2026
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the…
ModificadaAlta (7.5)1.4%—Zohocorp Manageengine Assetexplorer19/7/202117/6/2026
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request…
ModificadaAlta (7.5)4.5%—Zohocorp Manageengine Assetexplorer19/7/202117/6/2026
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be executed (due to authtoken validation), the…
ModificadaAlta (7.5)23%—Microsoft Internet Explorer11/5/202117/6/2026
Scripting Engine Memory Corruption Vulnerability
AnalizadaAlta (8.8)5.4%⚠ Explotación activaMicrosoft Internet Explorer11/3/202119/8/2026
Internet Explorer Remote Code Execution Vulnerability
AnalizadaAlta (8.8)81%⚠ Explotación activa💥 PoCMicrosoft EdgeMicrosoft Internet Explorer11/3/20211/10/2026
Internet Explorer Memory Corruption Vulnerability
Orbitaley — Vulnerabilidades