Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.38%—Mingocommerce Delete ALL PostsAI17/4/202517/6/2026
Missing Authorization vulnerability in mingocommerce Delete All Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Delete All Posts: through 1.1.1.
AplazadaAlta (7.5)0.57%—PHPAIAwplife Coming Soon Maintenance ModeAI15/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mobeen Abdullah Coming Soon, Maintenance Mode site-mode allows PHP Local File Inclusion.This issue affects Coming Soon, Maintenance Mode: from n/a through <= 1.1.1.
AplazadaAlta (8.1)0.93%—Roninwp FAT Coming SoonAI11/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Cooming Soon fat-coming-soon allows PHP Local File Inclusion.This issue affects FAT Cooming Soon: from n/a through <= 1.1.
AnalizadaMedia (6.7)0.17%—Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+2579/4/202517/6/2026
Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
AplazadaCrítica (9.1)0.67%💥 PoCNiteothemes CMP Coming Soon MaintenanceAI4/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.
AplazadaAlta (8.1)1.3%—Countdown Coming Soon Maintenance Countdown ClockAI4/4/202517/6/2026
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.9.1 via the createCdObj function. This makes it possible for unauthenticated attackers to include and execute files with the specific filenames on the server,…
AplazadaAlta (7.1)0.13%—Admingeekz Varnish-wpAI31/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AdminGeekZ Varnish WordPress varnish-wp allows Cross Site Request Forgery.This issue affects Varnish WordPress: from n/a through <= 1.7.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.
AnalizadaAlta (7.5)0.45%—Libming27/3/202517/6/2026
An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.
AnalizadaMedia (6.5)0.35%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.
AnalizadaMedia (6.5)0.35%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
AnalizadaAlta (7.5)0.45%—Libming27/3/202517/6/2026
An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.
AnalizadaMedia (6.5)0.34%—Libming27/3/202517/6/2026
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.
AnalizadaMedia (5.3)0.27%—Mingyuefusu Library Management System27/3/202517/6/2026
A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaMedia (5.3)0.44%—Mingyuefusu Library Management System27/3/202517/6/2026
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. This vulnerability affects the function getBookList of the file /admin/bookList?page=1&limit=10. The manipulation of the argument condition leads to sql injection. The…
AplazadaMedia (6.9)0.46%—Mingyuefusu TushuguanlixitongAI24/3/202517/6/2026
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leads to improper access…
AplazadaMedia (5.3)0.30%—Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP SystemAI17/3/202517/6/2026
A vulnerability was found in Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /Kfxt/Service.asmx of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to sql injection.…
Orbitaley — Vulnerabilidades