Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1895 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 0.86% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+5 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) mishandles reject messages. | |
| Modificada | Media (6.5) | 0.49% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+5 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_rmSend with incorrect values. | |
| Modificada | Media (5.4) | 0.68% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+8 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncReqPlainText before pairing is complete. | |
| Modificada | Media (5.4) | 0.64% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+5 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in legacy pairing. | |
| Modificada | Alta (7.5) | 0.77% | — | Microchip Bm78 FirmwareMicrochip Bm83 FirmwareMicrochip Rn4870 FirmwareMicrochip Rn4871 Firmware+10 | 19/12/2022 | 17/6/2026 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero. | |
| Modificada | Alta (7.5) | 0.89% | — | Kodcloud Kodexplorer | 6/12/2022 | 17/6/2026 | Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed by arbitrary users. This issue has been… | |
| Modificada | Media (6.5) | 3.2% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer | 23/11/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module. | |
| Modificada | Media (4.9) | 3.7% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer | 23/11/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure. | |
| Modificada | Media (5.3) | 0.56% | — | Jenkins S3 Explorer | 19/10/2022 | 17/6/2026 | Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it. | |
| Modificada | Crítica (9.8) | 1.7% | — | 10-strike Network Inventory Explorer | 23/9/2022 | 17/6/2026 | 10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function. | |
| Modificada | Alta (7.5) | 6.2% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer | 12/7/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.) | |
| Modificada | Alta (7.8) | 0.29% | — | Naver Cloud Explorer | 13/6/2022 | 17/6/2026 | Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection. | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (7.8) | 0.46% | — | Systemexplorer System Explorer | 4/4/2022 | 17/6/2026 | An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path. | |
| Modificada | Media (4.3) | 1.6% | — | Microsoft Azure Data Explorer | 9/2/2022 | 17/6/2026 | Azure Data Explorer Spoofing Vulnerability | |
| Modificada | Alta (7.8) | 0.81% | — | Opendesign Drawings Explorer | 21/12/2021 | 17/6/2026 | An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer before 2022.12. The specific issue exists after loading BMP files. Unchecked input data from a crafted BMP file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute… | |
| Modificada | Alta (7.8) | 0.84% | — | Opendesign Drawings Explorer | 5/12/2021 | 17/6/2026 | An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer before 2022.11. The specific issue exists after loading TIF files. Crafted data in a TIF file can trigger a write operation past the end of an allocated buffer. An attacker can leverage this… | |
| Modificada | Media (4.6) | 0.42% | — | File Explorer Project File Explorer | 22/10/2021 | 17/6/2026 | An issue in the authentication mechanism in Nong Ge File Explorer v1.4 unauthenticated allows to access sensitive data. | |
| Modificada | Media (6.5) | 0.56% | — | Netexplorer MY Smtp Contact | 10/8/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site. | |
| Modificada | Crítica (9.8) | 7.4% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the… | |
| Modificada | Alta (7.5) | 1.4% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request… | |
| Modificada | Alta (7.5) | 4.5% | — | Zohocorp Manageengine Assetexplorer | 19/7/2021 | 17/6/2026 | Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be executed (due to authtoken validation), the… | |
| Modificada | Alta (7.5) | 23% | — | Microsoft Internet Explorer | 11/5/2021 | 17/6/2026 | Scripting Engine Memory Corruption Vulnerability | |
| Analizada | Alta (8.8) | 5.4% | ⚠ Explotación activa | Microsoft Internet Explorer | 11/3/2021 | 19/8/2026 | Internet Explorer Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 81% | ⚠ Explotación activa💥 PoC | Microsoft EdgeMicrosoft Internet Explorer | 11/3/2021 | 1/10/2026 | Internet Explorer Memory Corruption Vulnerability |