Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1956 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.62% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 18/9/2023 | 17/6/2026 | Ciertos productos WithSecure permiten un bucle infinito en un motor de escaneo a través de tipos de archivos no especificados. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones posteriores,… | |
| Modificada | Alta (7.5) | 0.62% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 18/9/2023 | 17/6/2026 | Ciertos productos WithSecure permiten un bloqueo remoto de un motor de escaneo mediante el desempaquetado de un archivo PE. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones posteriores, WithSecure… | |
| Modificada | Alta (7.5) | 0.62% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 18/9/2023 | 17/6/2026 | Ciertos productos WithSecure permiten un bloqueo remoto de un motor de escaneo a través del procesamiento de una estructura de importación en un archivo PE. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y… | |
| Modificada | Alta (7.5) | 0.62% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 18/9/2023 | 17/6/2026 | Ciertos productos WithSecure permiten un bloqueo remoto de un motor de escaneo a través del procesamiento de un archivo comprimido. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones posteriores,… | |
| Modificada | Alta (7.5) | 0.62% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 18/9/2023 | 17/6/2026 | Algunos productos WithSecure permiten un bloqueo remoto de un motor de escaneo a través de la descompresión de archivos de datos manipulados. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones… | |
| Modificada | Alta (7.5) | 0.62% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 18/9/2023 | 17/6/2026 | Ciertos productos WithSecure permiten un bloqueo remoto de un motor de escaneo mediante el desempaquetado de archivos de datos manipulados. Esto afecta a WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email y Server Security 15, WithSecure Elements Endpoint Protection 17 y versiones… | |
| Modificada | Media (4.3) | 0.58% | — | Wpmet Metform Elementor Contact Form Builder | 31/8/2023 | 17/6/2026 | El Metform Elementor Contact Form Builder para WordPress es vulnerable a la revelación de información a través del shortcode 'mf_first_name' en versiones hasta la 3.3.1, inclusive. Esto permite a atacantes autenticados, con capacidades de nivel de suscriptor o superior, obtener información sensible sobre envíos de… | |
| Modificada | Media (6.1) | 0.37% | — | Wpdeveloper Essential Addons FOR Elementor | 29/8/2023 | 17/6/2026 | Vulnerabilidad de cross-site scripting (XSS) reflejado no autorizado en el plugin WPDeveloper Essential Addons for Elementor Pro versiones <= 5.4.8. | |
| Modificada | Media (6.1) | 3.4% | 💥 Exploit | Elementor Website Builder | 14/8/2023 | 17/6/2026 | The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs. | |
| Modificada | Alta (7.8) | 0.10% | — | Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+67 | 11/8/2023 | 17/6/2026 | Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.4) | 0.11% | — | Intel NUC Performance KIT AND Mini PC Nuc10i3fnh FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhf FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhfa FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhja Firmware+170 | 11/8/2023 | 17/6/2026 | Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+67 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.17% | — | Intel NUC KIT Nuc6cayh FirmwareIntel NUC KIT Nuc6cays FirmwareIntel NUC Mini PC Nuc7i3bnhxf FirmwareIntel NUC Mini PC Nuc7i3bnk Firmware+63 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (6.7) | 0.17% | — | Intel NUC 13 Extreme Compute Element Nuc13sbbi5 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7f Firmware+151 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 13 Extreme Compute Element Nuc13sbbi7f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi9f FirmwareIntel NUC 13 Extreme KIT Nuc13rngi7 Firmware+107 | 11/8/2023 | 17/6/2026 | Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board and Intel(R) NUC Pro Mini PC BIOS firmware may… | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 7 Enthusiast Nuc7i7bnkq FirmwareIntel NUC 7 Enthusiast Nuc7i7bnhxg FirmwareIntel NUC KIT Nuc7i7dnhe FirmwareIntel NUC KIT Nuc7i7dnke Firmware+207 | 11/8/2023 | 17/6/2026 | La inicialización incorrecta en Intel(R) NUC BIOS firmware pueden permitir que un usuario privilegiado habilite potencialmente la divulgación de información a través del acceso local. | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 11 Performance KIT Nuc11pahi3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11paki3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi5 Firmware+84 | 11/8/2023 | 17/6/2026 | El uso de recursos no inicializados en algunos firmware de BIOS de Intel(R) NUC puede permitir que un usuario con privilegios permita potencialmente la divulgación de información mediante acceso local. | |
| Modificada | Media (6.7) | 0.16% | — | Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+30 | 11/8/2023 | 17/6/2026 | Las restricciones de búfer inadecuadas en algunos firmware de BIOS de Intel(R) NUC pueden permitir que un usuario con privilegios habilite potencialmente la escalada de privilegios a través del acceso local. | |
| Modificada | Media (6.5) | 2.8% | — | MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+3 | 7/8/2023 | 17/6/2026 | lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count. | |
| Modificada | Alta (7.5) | 0.53% | 💥 PoC | Element55 Knowmore | 3/8/2023 | 17/6/2026 | Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext. | |
| Analizada | Crítica (9.8) | 0.57% | — | CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+4 | 25/7/2023 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of… | |
| Modificada | Media (4.8) | 0.48% | — | Premio MY Sticky Elements | 24/7/2023 | 17/6/2026 | The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.3) | 0.59% | — | Wpdeveloper Essential Addons FOR Elementor | 20/7/2023 | 17/6/2026 | The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's… | |
| Modificada | Alta (8.8) | 0.26% | — | Staxwp Visibility Logic FOR Elementor | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StaxWP Visibility Logic for Elementor plugin <= 2.3.4 versions. | |
| Modificada | Media (5.3) | 0.57% | — | Royal-elementor-addons Royal Elementor Addons | 18/7/2023 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 1.3.70 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's MailChimp… |