Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

334 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.17%—Openatom Openharmony2/2/202417/6/2026
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.
ModificadaMedia (5.5)0.15%—Openatom Openharmony2/2/202417/6/2026
in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.
ModificadaAlta (8.8)0.29%—Openatom Openharmony2/2/202417/6/2026
in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.
ModificadaMedia (5.5)0.15%—Openatom Openharmony2/2/202417/6/2026
in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.
ModificadaAlta (7.8)0.37%—Openatom Openeuler18/1/202417/6/2026
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
ModificadaMedia (5.5)0.34%—Openatom Openeuler18/1/202417/6/2026
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.
ModificadaBaja (3.3)0.15%—Openatom Openharmony2/1/202417/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.
ModificadaMedia (5.5)0.15%—Openatom Openharmony2/1/202417/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.
ModificadaMedia (5.5)0.15%—Openatom Openharmony2/1/202417/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.
ModificadaMedia (5.5)0.15%—Openatom Openharmony2/1/202417/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.
ModificadaMedia (5.5)0.14%—Openatom Openharmony2/1/202417/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources
ModificadaAlta (8.8)0.29%—Creatomatic Csprite18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Creatomatic Ltd CSprite.This issue affects CSprite: from n/a through 1.1.
ModificadaAlta (7.8)0.23%—Openatom Openharmony20/11/202317/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion.
ModificadaMedia (5.5)0.20%—Openatom Openharmony20/11/202317/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow.
ModificadaMedia (5.5)0.21%—Openatom Openharmony20/11/202317/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion.
ModificadaMedia (5.5)0.21%—Openatom Openharmony20/11/202317/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource.
ModificadaAlta (7.8)0.19%—Openatom Openharmony20/11/202317/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.
ModificadaMedia (5.5)0.19%—Openatom Openharmony20/11/202317/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.
ModificadaAlta (7.1)0.18%—Openatom Openharmony20/11/202317/6/2026
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions.
ModificadaAlta (8)0.40%—Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+62514/11/202317/6/2026
Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaBaja (3.5)0.30%—Intel Atom X6200fe FirmwareIntel Atom X6211e FirmwareIntel Atom X6212re FirmwareIntel Atom X6413e Firmware+62514/11/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
ModificadaCrítica (9.8)0.88%—Atomicwebstrategy Woocommerce Ninja Forms Product Add-ons6/11/202317/6/2026
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
ModificadaMedia (5.4)0.68%—Braekling Connect Matomo22/9/202317/6/2026
The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik' shortcode in versions up to, and including, 1.0.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (5.5)0.16%—Openatom Openharmony21/9/202317/6/2026
OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input.
ModificadaAlta (8)0.35%—Intel Celeron J6413 FirmwareIntel Celeron N6211 FirmwareIntel Pentium J6425 FirmwareIntel Pentium N6415 Firmware+29411/8/202317/6/2026
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.