Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.4) | 0.21% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.4) | 0.21% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.4) | 0.21% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3-07ada05 FirmwareLenovo Ideacentre 3-07imb05 FirmwareLenovo Ideacentre 5 14iab7 Firmware+107 | 8/11/2023 | 17/6/2026 | A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. | |
| Modificada | Media (5.4) | 0.52% | — | Eralion Neon Text | 27/10/2023 | 17/6/2026 | The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes (color). This makes it possible for authenticated attackers with… | |
| Analizada | Alta (7.8) | 0.51% | — | NeovimVIMFedoraproject Fedora | 11/10/2023 | 17/9/2026 | Use After Free in GitHub repository vim/vim prior to v9.0.2010. | |
| Modificada | Media (5.4) | 0.71% | — | Neos CMS | 18/9/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component. | |
| Modificada | Media (5.5) | 0.18% | — | Siemens Simatic PCS NEO | 14/9/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the Administration Console could get the credentials,… | |
| Analizada | Alta (7.8) | 0.61% | — | NeovimVIMDebian LinuxApple Macos | 5/9/2023 | 17/9/2026 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873. | |
| Analizada | Alta (7.8) | 0.56% | — | NeovimVIMFedoraproject FedoraDebian Linux+1 | 4/9/2023 | 17/9/2026 | Use After Free in GitHub repository vim/vim prior to 9.0.1858. | |
| Analizada | Alta (7.8) | 0.53% | — | NeovimVIMFedoraproject FedoraApple Macos | 4/9/2023 | 17/9/2026 | Use After Free in GitHub repository vim/vim prior to 9.0.1857. | |
| Analizada | Alta (7.8) | 0.54% | — | NeovimVIMFedoraproject FedoraApple Macos | 4/9/2023 | 18/9/2026 | Use After Free in GitHub repository vim/vim prior to 9.0.1840. | |
| Analizada | Alta (7.8) | 0.56% | — | NeovimVIMApple Macos | 3/9/2023 | 17/9/2026 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. | |
| Analizada | Alta (7.8) | 0.60% | — | Debian LinuxNeovimVIMApple Macos | 2/9/2023 | 18/9/2026 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848. | |
| Analizada | Alta (7.8) | 0.58% | — | NeovimVIMApple Macos | 2/9/2023 | 18/9/2026 | Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846. | |
| Modificada | Media (6.1) | 0.58% | — | Neomind Fusion Platform | 25/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in NeoMind Fusion Platform up to 20230731. Affected is an unknown function of the file /fusion/portal/action/Link. The manipulation of the argument link leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Media (4.8) | 0.34% | — | Neofrag | 31/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in neofarg-cms 0.2.3 allows remoate attacker to run arbitrary code via the copyright field in copyright settings. | |
| Modificada | Media (4.8) | 0.50% | 💥 PoC | STL Neox Dial Centre | 22/6/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Neox Contact Center 2.3.9, via the serach_sms_api_name parameter to the SMA API search. |