Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
366 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.70% | — | Jenkins Neuvector Vulnerability Scanner | 19/10/2022 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download. | |
| Modificada | Media (5.5) | 0.19% | — | Intel Standard ManageabilityIntel Active Management Technology Firmware | 18/8/2022 | 17/6/2026 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 0.88% | — | Intel Standard ManageabilityIntel Active Management Technology Firmware | 18/8/2022 | 17/6/2026 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access. | |
| Modificada | Media (6.8) | 0.37% | — | Intel Standard ManageabilityIntel Active Management Technology Firmware | 18/8/2022 | 17/6/2026 | Improper access control in firmware for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Alta (7.8) | 1.00% | — | Usabilitydynamics Wp-crm | 13/6/2022 | 17/6/2026 | The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability. | |
| Modificada | Alta (7.5) | 0.47% | — | Philips Interoperability Solution XDS | 25/5/2022 | 17/6/2026 | Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information when configured to use LDAP via TLS and where the domain controller returns LDAP referrals, which may allow an attacker to remotely read LDAP system credentials. | |
| Modificada | Media (6.7) | 0.24% | — | Intel In-band Manageability | 12/5/2022 | 17/6/2026 | Improper input validation in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.2) | 0.96% | — | Intel In-band Manageability | 12/5/2022 | 17/6/2026 | Improper access control in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (7.2) | 1.00% | — | IBM In-band Manageability | 12/5/2022 | 17/6/2026 | Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (8) | 0.39% | — | Intel Manageability Commander | 12/5/2022 | 17/6/2026 | Improper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Media (6.5) | 3.8% | — | Xmlsoft Libxml2Xmlsoft LibxsltFedoraproject FedoraDebian Linux+15 | 3/5/2022 | 17/6/2026 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for… | |
| Modificada | Alta (7.5) | 5.1% | — | Xmlsoft Libxml2Fedoraproject FedoraDebian LinuxApple Ipados+31 | 26/2/2022 | 17/6/2026 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Alta (8.8) | 1.3% | — | Offshorewebmaster Availability Calendar | 20/9/2021 | 17/6/2026 | The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+ | |
| Modificada | Media (4.8) | 0.62% | — | Offshorewebmaster Availability Calendar | 20/9/2021 | 17/6/2026 | The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Alta (7.4) | 50% | 💥 PoC | OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+28 | 24/8/2021 | 17/6/2026 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Modificada | Alta (8.8) | 0.82% | — | Roosty Diary-availability-calendar | 23/8/2021 | 17/6/2026 | The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is lacking any CSRF and capability check,… | |
| Modificada | Media (6.5) | 2.0% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesOracle ZFS Storage Appliance KITNetapp Active IQ Unified Manager+15 | 9/7/2021 | 17/6/2026 | A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. | |
| Modificada | Media (6.4) | 0.21% | — | Intel Local Manageability ServiceSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc427e Firmware+9 | 9/6/2021 | 17/6/2026 | Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.33% | — | Intel Converged Security AND Manageability EngineNetapp Cloud BackupSiemens Simatic Field PG M6 FirmwareSiemens Simatic Field PG M5 Firmware+10 | 9/6/2021 | 17/6/2026 | Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.8) | 0.27% | — | Intel Converged Security AND Manageability Engine | 9/6/2021 | 17/6/2026 | Modification of assumed-immutable data in subsystem in Intel(R) CSME versions before 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (4.4) | 0.28% | — | Intel Converged Security AND Manageability EngineSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e Firmware+9 | 9/6/2021 | 17/6/2026 | Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.28% | — | Intel Converged Security AND Manageability EngineSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc627e FirmwareSiemens Simatic Ipc647e Firmware+2 | 9/6/2021 | 17/6/2026 | Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (8.6) | 17% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Enterprise LinuxFedoraproject Fedora+24 | 19/5/2021 | 17/6/2026 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application… |