Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 28% | ⚠ Explotación activa💥 PoC | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+14 | 31/1/2024 | 7/8/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when… | |
| Modificada | Media (5.4) | 0.58% | — | Bootstrapped WP Recipe Maker | 18/1/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and wprm-recipe-counter shortcodes in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (6.1) | 0.67% | 💥 Exploit | Bootstrapped WP Recipe Maker | 18/1/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (5.4) | 0.34% | — | Bootstrapped WP Recipe Maker | 18/1/2024 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (6.1) | 0.33% | — | Ewels CPT Bootstrap Carousel | 8/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: from n/a through 1.12. | |
| Modificada | Media (5.4) | 0.30% | — | Addonmaster Bootstrap Shortcodes Ultimate | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akhtarujjaman Shuvo Bootstrap Shortcodes Ultimate allows Stored XSS.This issue affects Bootstrap Shortcodes Ultimate: from n/a through 4.3.1. | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Media (6.5) | 0.22% | — | Areoi ALL Bootstrap Blocks | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AREOI All Bootstrap Blocks plugin <= 1.3.6 versions. | |
| Modificada | Crítica (9.8) | 2.3% | — | Openbsd OpensshNetapp Brocade Fabric Operating SystemNetapp HCI Bootstrap OSNetapp Solidfire Element OS | 17/3/2023 | 14/7/2026 | ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. | |
| Modificada | Media (5.4) | 0.70% | — | Bootstrapped Easy Affiliate Links | 21/2/2023 | 17/6/2026 | The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.47% | — | Bootstrap Shortcodes Project Bootstrap Shortcodes | 21/2/2023 | 17/6/2026 | The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.53% | — | CPT Bootstrap Carousel Project CPT Bootstrap Carousel | 30/1/2023 | 17/6/2026 | The CPT Bootstrap Carousel WordPress plugin through 1.12 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (5.4) | 0.47% | — | Easy Bootstrap Shortcode Project Easy Bootstrap Shortcode | 23/1/2023 | 17/6/2026 | The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Media (6.1) | 0.61% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 20/1/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php. | |
| Modificada | Media (5.4) | 0.53% | — | Bootstrapped WP Recipe Maker | 9/1/2023 | 17/6/2026 | The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Alta (7.5) | 2.7% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+5 | 9/11/2022 | 17/6/2026 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote… | |
| Modificada | Baja (3.7) | 2.4% | — | Haxx CurlNetapp Clustered Data OntapNetapp Element SoftwareNetapp HCI Management Node+9 | 23/9/2022 | 17/6/2026 | When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings. | |
| Modificada | Media (6.5) | 1.7% | — | GnutlsRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+1 | 24/8/2022 | 17/6/2026 | A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances. | |
| Modificada | Media (6.1) | 0.59% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 18/8/2022 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php. | |
| Modificada | Media (5.5) | 0.32% | — | Linux KernelDebian LinuxNetapp A700s FirmwareNetapp Active IQ Unified Manager+20 | 27/7/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. | |
| Modificada | Media (5.9) | 7.5% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+10 | 7/7/2022 | 17/6/2026 | When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client. | |
| Modificada | Crítica (9.8) | 7.7% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+10 | 7/7/2022 | 17/6/2026 | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file… | |
| Modificada | Media (6.5) | 33% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+15 | 7/7/2022 | 17/6/2026 | curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of… | |
| Modificada | Alta (7.3) | 95% | — | OpensslDebian LinuxFedoraproject FedoraSiemens Sinec INS+24 | 21/6/2022 | 17/6/2026 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in… | |
| Modificada | Media (4.3) | 1.3% | — | Haxx CurlNetapp HCI Bootstrap OSNetapp Clustered Data OntapNetapp Solidfire, Enterprise SDS & HCI Storage Node+6 | 2/6/2022 | 17/6/2026 | Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by… |