Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 0.40% | — | Simplemachines Simple Machines Forum | 21/3/2025 | 17/6/2026 | A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The manipulation of the argument Notice leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Semantic-machines VedaAI | 5/3/2025 | 17/6/2026 | The VEDA - MultiPurpose WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.2 via deserialization of untrusted input in the 'veda_backup_and_restore_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Media (5.5) | 0.14% | — | Dell Recoverpoint FOR Virtual Machines | 20/2/2025 | 17/6/2026 | Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the system. | |
| Analizada | Alta (7.8) | 0.16% | — | Dell Recoverpoint FOR Virtual Machines | 20/2/2025 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running the specific binary and perform any administrative action permitted by it resulting in shutting down the server, modifying… | |
| Aplazada | Crítica (10) | 0.51% | — | BSS Software Mobuy Online Machinery Monitoring PanelAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0. | |
| Analizada | Media (4.2) | 0.25% | — | Oracle Java Virtual Machine | 21/1/2025 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.… | |
| Aplazada | Media (6.4) | 0.34% | — | JSM Screenshot Machine ShortcodeAI | 18/1/2025 | 17/6/2026 | The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ssm' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.6) | 0.66% | — | Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAI | 14/1/2025 | 17/6/2026 | Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products. | |
| Analizada | Media (6.5) | 0.47% | — | Dell Recoverpoint FOR Virtual Machines | 13/12/2024 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could potentially exploit this vulnerability, leading to the disruption of most functionalities of the RPA persistent after reboot, resulting in need of technical support intervention in getting system back… | |
| Analizada | Crítica (9.8) | 0.55% | — | Dell Recoverpoint FOR Virtual Machines | 13/12/2024 | 17/6/2026 | Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (5.5) | 0.19% | — | Dell Recoverpoint FOR Virtual Machines | 13/12/2024 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time. | |
| Analizada | Media (6.5) | 0.56% | — | Dell Recoverpoint FOR Virtual Machines | 13/12/2024 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information | |
| Modificada | Crítica (9.8) | 0.41% | — | Dell Recoverpoint FOR Virtual Machines | 13/12/2024 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to… | |
| Analizada | Crítica (9.8) | 0.32% | — | Dell Recoverpoint FOR Virtual Machines | 13/12/2024 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete… | |
| Analizada | Alta (8.8) | 0.78% | — | Dell Recoverpoint FOR Virtual Machines | 13/12/2024 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system. | |
| Analizada | Alta (7.8) | 0.35% | — | Nomachine | 22/11/2024 | 17/6/2026 | NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.21% | — | Schneider-electric Vijeo DesignerSchneider-electric Vijeo Designer Embedded IN Ecostruxure Machine Expert | 11/9/2024 | 17/6/2026 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries. | |
| Analizada | Alta (7.8) | 0.51% | — | Microsoft Azure Connected Machine Agent | 13/8/2024 | 17/6/2026 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 0.63% | — | Microsoft Azure Connected Machine Agent | 13/8/2024 | 17/6/2026 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | |
| Analizada | Media (5.3) | 0.48% | — | Simplemachines Simple Machines Forum | 3/8/2024 | 17/6/2026 | A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper… | |
| Analizada | Media (5.3) | 0.44% | — | Simplemachines Simple Machines Forum | 3/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipulation of the argument aid leads to improper control of resource identifiers. It… | |
| Aplazada | Alta (7.5) | 0.39% | — | Skteco Central Control Attendance MachineAI | 26/7/2024 | 17/6/2026 | An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component. | |
| Aplazada | Alta (7.8) | 0.57% | — | Thecodingmachine GotenbergAI | 19/7/2024 | 2/7/2026 | Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook before 8.1.0 are vulnerable to Server-side Request Forgery… | |
| Modificada | Alta (8.1) | 1.1% | — | Microsoft Azure Data Science Virtual Machine | 11/6/2024 | 20/7/2026 | Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability | |
| Analizada | Media (5.3) | 0.43% | — | Oracle Java Virtual Machine | 16/4/2024 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful… |