Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

444 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.13%—UpdatenaviAIUpdatenaviinstallserviceAI12/6/202517/6/2026
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
AnalizadaAlta (7.8)0.39%—Microsoft Autoupdate10/6/202517/6/2026
Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
AplazadaMedia (5.9)0.34%—Abup Cloud Update PlatformAI23/5/202517/6/2026
Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the ABUP Cloud…
AnalizadaAlta (8.8)0.58%💥 PoCMicrosoft Edge Update22/5/202517/6/2026
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
AplazadaMedia (5.4)0.13%—Intel Ethernet Network Adapter E810 NVM Update UtilityAI13/5/202517/6/2026
Insecure inherited permissions in the NVM Update Utility for some Intel(R) Ethernet Network Adapter E810 Series before version 4.60 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.3)0.28%—Patch MY PC Home UpdaterAI9/5/202517/6/2026
A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects some unknown processing in the library…
AplazadaMedia (5.9)0.22%—Devignstudiosltd Covid-19 Coronavirus Update Your CustomersAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 (Coronavirus) Update Your Customers: from n/a through <= 1.5.1.
AplazadaAlta (8.8)0.37%—Aweos Gmbh Email Notifications FOR UpdatesAI15/4/202517/6/2026
Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6.
AplazadaAlta (7.1)0.42%—Rachel Cherry Lock Your UpdatesAI11/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rachel Cherry Lock Your Updates lock-your-updates allows Reflected XSS.This issue affects Lock Your Updates: from n/a through <= 1.1.
AnalizadaAlta (7.8)1.1%—Microsoft Autoupdate8/4/202517/6/2026
Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)1.1%—Microsoft Autoupdate8/4/202517/6/2026
Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.8)0.39%—Email Notifications FOR UpdatesAI5/4/202517/6/2026
The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the awun_import_settings() function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers,…
AnalizadaMedia (6.9)0.32%—Bitdefender Gravityzone Update Server4/4/202517/6/2026
A server-side request forgery (SSRF) vulnerability exists in the Bitdefender GravityZone Update Server when operating in Relay Mode. The HTTP proxy component on port 7074 uses a domain allowlist to restrict outbound requests, but fails to properly sanitize hostnames containing null-byte (%00) sequences. By crafting a…
ModificadaAlta (7.4)14%—Gnome YelpDebian LinuxRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64+173/4/202529/6/2026
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
AplazadaAlta (7.1)0.29%—David Wood Latest Custom Post Type UpdatesAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Wood Latest Custom Post Type Updates latest-custom-post-type-updates allows Reflected XSS.This issue affects Latest Custom Post Type Updates: from n/a through <= 1.3.0.
ModificadaMedia (6.5)0.86%—Gnome LibsoupRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR Arm64 EUS+173/4/202530/6/2026
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.
AnalizadaAlta (7.8)0.40%—Microsoft Edge Update23/3/202517/6/2026
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
AplazadaMedia (4.3)0.17%—Fastmover Plugins Last Updated ColumnAI11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fastmover Plugins Last Updated Column plugins-last-updated-column allows Cross Site Request Forgery.This issue affects Plugins Last Updated Column: from n/a through <= 0.1.3.
AplazadaAlta (7.1)0.29%—Devu Status UpdaterAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devu Status Updater fb-status-updater allows Reflected XSS.This issue affects Status Updater: from n/a through <= 1.9.2.
AplazadaMedia (6.5)0.37%—Codingkart WOO Update Variations IN CartAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codingkart Woo Update Variations In Cart woo-update-variations-in-cart allows Stored XSS.This issue affects Woo Update Variations In Cart: from n/a through <= 0.0.9.
AplazadaAlta (7.1)0.28%—Michael Stursberg Browser-update-notifyAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Stursberg Browser-Update-Notify browser-update-notify allows Reflected XSS.This issue affects Browser-Update-Notify: from n/a through <= 0.2.1.
AnalizadaAlta (7.8)0.16%—Mongodb MongoshRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64 EUSRedhat Codeready Linux Builder FOR IBM Z Systems EUS+927/2/202517/6/2026
mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0
AnalizadaAlta (7.8)0.15%—Mongodb CompassRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux Server FOR Power Little Endian Update Services FOR SAP Solutions+127/2/202517/6/2026
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
AnalizadaMedia (4.3)0.17%—Exeebit Disable Auto Updates19/2/202517/6/2026
The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged…
AplazadaMedia (5.4)0.19%—Intel Server M50fcp Bios AND System Firmware Update PackageAI12/2/202517/6/2026
Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family before version R01.02.0002 may allow a privileged user to potentially enable escalation of privilege via local access.