Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.2)0.17%—Dell Alienware 13 R2 FirmwareDell Alienware 13 R3 FirmwareDell Alienware 15 R2 FirmwareDell Alienware 15 R3 Firmware+15310/2/202317/6/2026
Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to read system information via debug interfaces.
ModificadaMedia (5.1)0.16%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Chengming 3900 FirmwareDell G15 5510 Firmware+1851/2/202317/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
ModificadaCrítica (9.8)2.1%💥 PoCAidreform Project AidreformChimpgroup BolsterChimpgroup SpikesChimpgroup Westand+623/1/202317/6/2026
The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill…
AnalizadaAlta (7.2)0.72%—Ad33lx IP Blacklist Cloud17/1/202317/6/2026
Auth. SQL Injection (SQLi) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
AnalizadaMedia (4.8)0.39%—Ad33lx IP Blacklist Cloud17/1/202317/6/2026
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
ModificadaAlta (7.5)0.88%—Blackbox Acr1000a-r-r2 FirmwareBlackbox Acr1000a-t-r2 FirmwareBlackbox Acr1002a-r FirmwareBlackbox Acr1002a-t Firmware+110/1/202317/6/2026
Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.
ModificadaMedia (6.5)1.4%💥 PoCBlackboard Learn5/9/202217/6/2026
Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating this cannot be reproduced.
ModificadaMedia (5.4)0.64%—Blackrainbow Nimbus2/6/202217/6/2026
Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).
ModificadaMedia (6.1)0.83%—Synopsys Black Duck HUB10/5/202217/6/2026
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of user-supplied input to MadCap Flare's framework embedded within Black Duck Hub's Help Documentation…
ModificadaCrítica (9.1)1.7%—Plugin-planet Blackhole FOR BAD Bots4/4/202217/6/2026
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots.…
ModificadaMedia (6.1)0.50%—IBM ISS Blackice PC Protection28/3/202216/6/2026
A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipulation with an unknown input leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This…
ModificadaMedia (5.3)0.41%—IBM ISS Blackice PC Protection28/3/202216/6/2026
A vulnerability was found in ISS BlackICE PC Protection. It has been declared as problematic. Affected by this vulnerability is the component Update Handler which allows cleartext transmission of data. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaCrítica (9.8)1.0%—IBM ISS Blackice PC Protection28/3/202216/6/2026
A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Detection. The manipulation as part of POST/PUT/DELETE/OPTIONS Request leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to…
ModificadaCrítica (9.1)1.5%—Vmware Carbon Black APP Control23/3/202217/6/2026
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where…
ModificadaCrítica (9.1)20%—Vmware Carbon Black APP Control23/3/202217/6/2026
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute…
ModificadaAlta (7.8)0.18%—Blackberry QNX MomenticsBlackberry QNX Software Development PlatformBlackberry QNX OS FOR MedicalBlackberry QNX OS FOR Safety10/3/202217/6/2026
An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX…
ModificadaMedia (5.1)0.14%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+2109/2/202217/6/2026
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.
ModificadaAlta (7.2)0.26%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+2109/2/202217/6/2026
Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
ModificadaCrítica (9.8)18%—Blackmagicdesign Davinci Resolve22/12/202117/6/2026
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID that was parsed from a frame within the video container. Upon destruction of the object that owns it, the uninitialized member will be…
ModificadaCrítica (9.8)16%—Blackmagicdesign Davinci Resolve22/12/202117/6/2026
When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate the size of a heap buffer. Due to an integer overflow with regards…
ModificadaCrítica (9.8)1.8%—Blackberry QNX Software Development Platform13/12/202117/6/2026
A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process.
ModificadaAlta (7.5)1.7%—Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+2124/11/202117/6/2026
A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings…
ModificadaCrítica (9.8)3.3%—Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+2224/11/202117/6/2026
A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client…
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.
ModificadaMedia (4.4)0.21%—Nvidia Dgx-1 P100Nvidia Dgx-1 V100Nvidia Dgx-2Nvidia DGX Station A100+13120/11/202117/6/2026
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.