Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1956 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.62%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+318/9/202317/6/2026
Ciertos productos WithSecure permiten un bucle infinito en un motor de escaneo a través de tipos de archivos no especificados. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones posteriores,…
ModificadaAlta (7.5)0.62%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+318/9/202317/6/2026
Ciertos productos WithSecure permiten un bloqueo remoto de un motor de escaneo mediante el desempaquetado de un archivo PE. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones posteriores, WithSecure…
ModificadaAlta (7.5)0.62%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+318/9/202317/6/2026
Ciertos productos WithSecure permiten un bloqueo remoto de un motor de escaneo a través del procesamiento de una estructura de importación en un archivo PE. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y…
ModificadaAlta (7.5)0.62%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+318/9/202317/6/2026
Ciertos productos WithSecure permiten un bloqueo remoto de un motor de escaneo a través del procesamiento de un archivo comprimido. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones posteriores,…
ModificadaAlta (7.5)0.62%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+318/9/202317/6/2026
Algunos productos WithSecure permiten un bloqueo remoto de un motor de escaneo a través de la descompresión de archivos de datos manipulados. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones…
ModificadaAlta (7.5)0.62%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+318/9/202317/6/2026
Ciertos productos WithSecure permiten un bloqueo remoto de un motor de escaneo mediante el desempaquetado de archivos de datos manipulados. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones…
ModificadaMedia (4.3)0.58%—Wpmet Metform Elementor Contact Form Builder31/8/202317/6/2026
El Metform Elementor Contact Form Builder para WordPress es vulnerable a la revelación de información a través del shortcode 'mf_first_name' en versiones hasta la 3.3.1, inclusive. Esto permite a atacantes autenticados, con capacidades de nivel de suscriptor o superior, obtener información sensible sobre envíos de…
ModificadaMedia (6.1)0.37%—Wpdeveloper Essential Addons FOR Elementor29/8/202317/6/2026
Vulnerabilidad de cross-site scripting (XSS) reflejado no autorizado en el plugin WPDeveloper Essential Addons for Elementor Pro versiones <= 5.4.8.
ModificadaMedia (6.1)3.4%💥 ExploitElementor Website Builder14/8/202317/6/2026
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
ModificadaAlta (7.8)0.10%—Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+6711/8/202317/6/2026
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.4)0.11%—Intel NUC Performance KIT AND Mini PC Nuc10i3fnh FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhf FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhfa FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhja Firmware+17011/8/202317/6/2026
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.19%—Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+6711/8/202317/6/2026
Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.17%—Intel NUC KIT Nuc6cayh FirmwareIntel NUC KIT Nuc6cays FirmwareIntel NUC Mini PC Nuc7i3bnhxf FirmwareIntel NUC Mini PC Nuc7i3bnk Firmware+6311/8/202317/6/2026
Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (6.7)0.17%—Intel NUC 13 Extreme Compute Element Nuc13sbbi5 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7f Firmware+15111/8/202317/6/2026
Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.19%—Intel NUC 13 Extreme Compute Element Nuc13sbbi7f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi9f FirmwareIntel NUC 13 Extreme KIT Nuc13rngi7 Firmware+10711/8/202317/6/2026
Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board and Intel(R) NUC Pro Mini PC BIOS firmware may…
ModificadaMedia (4.4)0.19%—Intel NUC 7 Enthusiast Nuc7i7bnkq FirmwareIntel NUC 7 Enthusiast Nuc7i7bnhxg FirmwareIntel NUC KIT Nuc7i7dnhe FirmwareIntel NUC KIT Nuc7i7dnke Firmware+20711/8/202317/6/2026
La inicialización incorrecta en Intel(R) NUC BIOS firmware pueden permitir que un usuario privilegiado habilite potencialmente la divulgación de información a través del acceso local.
ModificadaMedia (4.4)0.19%—Intel NUC 11 Performance KIT Nuc11pahi3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11paki3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi5 Firmware+8411/8/202317/6/2026
El uso de recursos no inicializados en algunos firmware de BIOS de Intel(R) NUC puede permitir que un usuario con privilegios permita potencialmente la divulgación de información mediante acceso local.
ModificadaMedia (6.7)0.16%—Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+3011/8/202317/6/2026
Las restricciones de búfer inadecuadas en algunos firmware de BIOS de Intel(R) NUC pueden permitir que un usuario con privilegios habilite potencialmente la escalada de privilegios a través del acceso local.
ModificadaMedia (6.5)2.8%—MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+37/8/202317/6/2026
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
ModificadaAlta (7.5)0.53%💥 PoCElement55 Knowmore3/8/202317/6/2026
Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
AnalizadaCrítica (9.8)0.57%—CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+425/7/202317/6/2026
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of…
ModificadaMedia (4.8)0.48%—Premio MY Sticky Elements24/7/202317/6/2026
The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.3)0.59%—Wpdeveloper Essential Addons FOR Elementor20/7/202317/6/2026
The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's…
ModificadaAlta (8.8)0.26%—Staxwp Visibility Logic FOR Elementor18/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StaxWP Visibility Logic for Elementor plugin <= 2.3.4 versions.
ModificadaMedia (5.3)0.57%—Royal-elementor-addons Royal Elementor Addons18/7/202317/6/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp…
Orbitaley — Vulnerabilidades