Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 6.6% | 💥 Exploit | Ligeo-archives Ligeo Basics | 17/3/2022 | 17/6/2026 | Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features. | |
| Modificada | Crítica (9.1) | 0.97% | — | Rambus Safezone Basic Crypto ModuleFujifilm Apeos C7070 FirmwareFujifilm Apeos C6570 FirmwareFujifilm Apeos C5570 Firmware+88 | 14/3/2022 | 17/6/2026 | The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows… | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (4.9) | 2.5% | — | Auerswald Compact 5500r IP FirmwareAuerswald Compact 5200r IP FirmwareAuerswald Compact 5000r IP FirmwareAuerswald Compact 4000 IP Firmware+6 | 13/12/2021 | 17/6/2026 | Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring. | |
| Modificada | Alta (8.8) | 2.1% | — | Auerswald Compact 5500r IP FirmwareAuerswald Compact 5200r IP FirmwareAuerswald Compact 5000r IP FirmwareAuerswald Compact 4000 IP Firmware+6 | 13/12/2021 | 17/6/2026 | Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring. | |
| Modificada | Crítica (9.8) | 2.5% | — | Circutor Compact Dc-s Basic Firmware | 2/12/2021 | 17/6/2026 | Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to execute arbitrary code. | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Media (6.5) | 0.56% | — | MI True Wireless Earbuds Basic 2 FirmwareBluetrum Ab5376t FirmwareBluetrum Bt8896a Firmware | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (either restart or deadlock the device) by flooding a device with LMP_AU_rand data. | |
| Modificada | Alta (7.5) | 2.6% | — | Opcfoundation Local Discover ServerSiemens Simatic Process Historian OPC UA Server FirmwareSiemens Simatic NET PCSiemens Simatic Wincc+3 | 27/8/2021 | 17/6/2026 | In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer. | |
| Modificada | Crítica (9.8) | 2.8% | — | Basic Shopping Cart Project Basic Shopping Cart | 30/7/2021 | 17/6/2026 | A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin. | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Alta (7.5) | 1.3% | — | Basic DSP Matrix Project Basic DSP Matrix | 26/1/2021 | 17/6/2026 | An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a double drop can be performed. | |
| Modificada | Crítica (9.8) | 1.5% | — | Siemens Simatic HMI Basic Panels 2ND Generation FirmwareSiemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Mobile Panels FirmwareSiemens Simatic HMI United Comfort Panels Firmware | 9/9/2020 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected… | |
| Modificada | Media (6.5) | 0.33% | — | Siemens Simatic HMI Basic Panels 1ST GenerationSiemens Simatic HMI Basic Panels 2ND GenerationSiemens Simatic Wincc Runtime AdvancedSiemens Simatic HMI Comfort Panels Firmware+2 | 14/7/2020 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC HMI KTP700F Mobile Arctic (All versions),… | |
| Modificada | Baja (2.4) | 0.36% | — | Django-basic-auth-ip-whitelist Project Django-basic-auth-ip-whitelist | 24/6/2020 | 17/6/2026 | In django-basic-auth-ip-whitelist before 0.3.4, a potential timing attack exists on websites where the basic authentication is used or configured, i.e. BASIC_AUTH_LOGIN and BASIC_AUTH_PASSWORD is set. Currently the string comparison between configured credentials and the ones provided by users is performed through a… | |
| Modificada | Media (5) | 0.95% | — | Semtech Lora Basics Station | 22/6/2020 | 17/6/2026 | In LoRa Basics Station before 2.0.4, there is a Use After Free vulnerability that leads to memory corruption. This bug is triggered on 32-bit machines when the CUPS server responds with a message (https://doc.sm.tc/station/cupsproto.html#http-post-response) where the signature length is larger than 2 GByte (never… | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Crítica (9.8) | 1.6% | — | Schneider-electric Ecostruxure Machine ExpertSchneider-electric Somachine BasicSchneider-electric Modicon M100 FirmwareSchneider-electric Modicon M200 Firmware+1 | 22/4/2020 | 17/6/2026 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens DK Standard Ethernet ControllerSiemens Profinet DriverSiemens Simatic IPC SupportSiemens Ek-ertec 200 Firmware+48 | 11/2/2020 | 17/6/2026 | Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack.… | |
| Modificada | Media (4.3) | 1.1% | — | Basic Webmail Project Basic Webmail | 8/2/2020 | 16/6/2026 | The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses. | |
| Modificada | Alta (7.8) | 0.78% | — | Yabasic | 13/12/2019 | 17/6/2026 | Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file. | |
| Modificada | Alta (8.8) | 1.2% | — | Yabasic | 11/12/2019 | 17/6/2026 | Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file. | |
| Modificada | Crítica (9.8) | 1.3% | — | Gatech Computing FOR Good's Basic Laboratory Information System | 6/11/2019 | 17/6/2026 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may alter several facets of a user account, including promoting any user to an administrator. | |
| Modificada | Media (5.3) | 0.90% | — | Gatech Computing FOR Good's Basic Laboratory Information System | 6/11/2019 | 17/6/2026 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may enumerate the user names and facility names in use on a particular installation. | |
| Modificada | Crítica (9.8) | 1.3% | — | Gatech Computing FOR Good's Basic Laboratory Information System | 6/11/2019 | 17/6/2026 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticated user may change the password of any administrator-level user. |