Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)0.40%—Simplemachines Simple Machines Forum21/3/202517/6/2026
A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The manipulation of the argument Notice leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the…
AplazadaCrítica (9.8)0.67%—Semantic-machines VedaAI5/3/202517/6/2026
The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deserialization of untrusted input in the 'veda_backup_and_restore_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and…
AnalizadaMedia (5.5)0.14%—Dell Recoverpoint FOR Virtual Machines20/2/202517/6/2026
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the system.
AnalizadaAlta (7.8)0.16%—Dell Recoverpoint FOR Virtual Machines20/2/202517/6/2026
Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running the specific binary and perform any administrative action permitted by it resulting in shutting down the server, modifying…
AplazadaCrítica (10)0.51%—BSS Software Mobuy Online Machinery Monitoring PanelAI14/2/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0.
AnalizadaMedia (4.2)0.25%—Oracle Java Virtual Machine21/1/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.…
AplazadaMedia (6.4)0.34%—JSM Screenshot Machine ShortcodeAI18/1/202517/6/2026
The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ssm' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaMedia (6.6)0.66%—Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAI14/1/202517/6/2026
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.
AnalizadaMedia (6.5)0.47%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could potentially exploit this vulnerability, leading to the disruption of most functionalities of the RPA persistent after reboot, resulting in need of technical support intervention in getting system back…
AnalizadaCrítica (9.8)0.55%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaMedia (5.5)0.19%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.
AnalizadaMedia (6.5)0.56%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information
ModificadaCrítica (9.8)0.41%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to…
AnalizadaCrítica (9.8)0.32%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete…
AnalizadaAlta (8.8)0.78%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system.
AnalizadaAlta (7.8)0.35%—Nomachine22/11/202417/6/2026
NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AnalizadaAlta (7.8)0.21%—Schneider-electric Vijeo DesignerSchneider-electric Vijeo Designer Embedded IN Ecostruxure Machine Expert11/9/202417/6/2026
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.
AnalizadaAlta (7.8)0.51%—Microsoft Azure Connected Machine Agent13/8/202417/6/2026
Azure Connected Machine Agent Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)0.63%—Microsoft Azure Connected Machine Agent13/8/202417/6/2026
Azure Connected Machine Agent Elevation of Privilege Vulnerability
AnalizadaMedia (5.3)0.48%—Simplemachines Simple Machines Forum3/8/202417/6/2026
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper…
AnalizadaMedia (5.3)0.44%—Simplemachines Simple Machines Forum3/8/202417/6/2026
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipulation of the argument aid leads to improper control of resource identifiers. It…
AplazadaAlta (7.5)0.39%—Skteco Central Control Attendance MachineAI26/7/202417/6/2026
An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component.
AplazadaAlta (7.8)0.57%—Thecodingmachine GotenbergAI19/7/20242/7/2026
Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook before 8.1.0 are vulnerable to Server-side Request Forgery…
ModificadaAlta (8.1)1.1%—Microsoft Azure Data Science Virtual Machine11/6/202420/7/2026
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
AnalizadaMedia (5.3)0.43%—Oracle Java Virtual Machine16/4/202417/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful…
Orbitaley — Vulnerabilidades