Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
253 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.19% | — | Dfeg Electronic Deliverables Creation Support Tool | 24/1/2024 | 17/6/2026 | Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be… | |
| Modificada | Media (5.5) | 0.23% | — | Cals-ed Electronic Delivery Check SystemCals-ed Electronic Delivery Item Inspection Support System | 24/1/2024 | 17/6/2026 | Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity… | |
| Modificada | Alta (7) | 0.21% | — | Electronjs Electron | 1/12/2023 | 17/6/2026 | Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. This only impacts apps that have the `embeddedAsarIntegrityValidation` and `onlyLoadAppFromAsar` fuses enabled. Apps without these fuses enabled are not impacted. This issue is specific to macOS as… | |
| Modificada | Media (6.6) | 0.49% | — | Electronjs Electron | 6/9/2023 | 17/6/2026 | Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted. Specifically this issue can only be exploited if the following conditions are met: 1. The app is launched with an… | |
| Modificada | Alta (8.5) | 0.59% | — | Electronjs Electron | 6/9/2023 | 17/6/2026 | Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps using `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated… | |
| Modificada | Crítica (9.8) | 0.66% | — | Electronjs Electron | 6/9/2023 | 17/6/2026 | Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that directive, is not respected in renderers that have sandbox disabled.… | |
| Modificada | Alta (8.8) | 0.79% | 💥 PoC | Heroelectronix Qubo Hcd01 FirmwareHeroelectronix Qubo Hcd02 Firmware | 4/7/2023 | 17/6/2026 | Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password. | |
| Modificada | Media (5.5) | 0.33% | — | Electronic Flexihub | 24/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 4.5% | 💥 Exploit | Agilebio Electronic LAB Notebook | 6/3/2023 | 17/6/2026 | AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability. | |
| Modificada | Crítica (9.8) | 0.74% | — | Electronic Medical Records System Project Electronic Medical Records System | 2/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Electronic Medical Records System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file administrator.php of the component Cookie Handler. The manipulation of the argument userid leads to sql injection. The attack can… | |
| Modificada | Alta (7.8) | 0.37% | — | Markdown-electron Project Markdown-electron | 24/2/2023 | 17/6/2026 | A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases… | |
| Modificada | Crítica (9.8) | 1.5% | — | Create-choo-electron Project Create-choo-electron | 26/1/2023 | 17/6/2026 | All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization. | |
| Modificada | Media (6.1) | 0.55% | — | Jacic Electronic Bidding Core System | 19/12/2022 | 17/6/2026 | Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL. | |
| Modificada | Media (6.1) | 0.56% | — | Jacic Electronic Bidding Core System | 19/12/2022 | 17/6/2026 | Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (6.1) | 0.57% | — | Jacic Electronic Bidding Core System | 19/12/2022 | 17/6/2026 | Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (6.5) | 0.73% | — | Electronic Shelf Label Protocol Project Electronic Shelf Label Protocol | 27/11/2022 | 17/6/2026 | The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 board, does not use authentication, which allows attackers to change label values via 433 MHz RF signals, as demonstrated by disrupting the organization of a hospital storage unit,… | |
| Modificada | Media (6.1) | 0.56% | — | Electronjs Electron | 8/11/2022 | 17/6/2026 | The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, Electron delays a check for redirecting to file:// URLs… | |
| Modificada | Alta (8.8) | 0.75% | — | Electronic Medical Records System Project Electronic Medical Records System | 6/8/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Electronic Medical Records System and classified as critical. This vulnerability affects unknown code of the file register.php of the component UPDATE Statement Handler. The manipulation of the argument pconsultation leads to sql injection. The attack can be initiated… | |
| Modificada | Crítica (9.8) | 0.75% | — | Electronic Medical Records System Project Electronic Medical Records System | 5/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Electronic Medical Records System and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument user_email leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.81% | — | Fahou100 Electronic Mall System | 14/7/2022 | 17/6/2026 | Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection. | |
| Modificada | Alta (7.2) | 0.89% | — | Electronjs Electron | 13/6/2022 | 17/6/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages… | |
| Modificada | Crítica (9.8) | 1.0% | — | Electronjs Electron | 13/6/2022 | 17/6/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with `nodeIntegrationInSubFrames` enabled which in… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+24 | 1/4/2022 | 17/6/2026 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | |
| Modificada | Media (5) | 0.95% | — | Electronjs Electron | 22/3/2022 | 17/6/2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth API if the app has not configured a… | |
| Modificada | Crítica (9.8) | 1.3% | — | Hegemonelectronics Plc4trucks Firmware | 10/3/2022 | 17/6/2026 | Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals. |