Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.19%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3 07ach7 FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07ada05 Firmware+1105/6/202317/6/2026
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
AnalizadaMedia (5.3)0.41%—Fedoraproject FedoraApple MacosNeovimVIM29/4/202324/9/2026
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
ModificadaMedia (6.1)0.48%—Ualberta Neosdiscovery5/3/202317/6/2026
A vulnerability was found in ualbertalib NEOSDiscovery 1.0.70 and classified as problematic. This issue affects some unknown processing of the file app/views/bookmarks/_refworks.html.erb. The manipulation leads to use of web link to untrusted target with window.opener access. The attack may be initiated remotely.…
AnalizadaMedia (6.6)0.45%—Debian LinuxFedoraproject FedoraNeovimVIM4/3/202318/9/2026
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
AnalizadaMedia (6.6)0.50%—Fedoraproject FedoraNeovimVIM3/3/202318/9/2026
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
ModificadaAlta (8.1)0.89%—Neo4j Awesome Procedures ON Cyper16/2/202317/6/2026
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior to version 5.5.0 and 4.4.0.14 (4.4 branch) in Neo4j graph database. XML External Entity (XXE) injection occurs when the XML parser allows…
ModificadaAlta (8.8)0.78%—Infineon Cypress Bluetooth Mesh Software Development KIT1/2/202317/6/2026
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write…
ModificadaAlta (8.8)0.78%—Infineon Cypress Bluetooth Mesh Software Development KIT1/2/202317/6/2026
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability…
ModificadaMedia (6.7)0.23%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+28330/1/202317/6/2026
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+14330/1/202317/6/2026
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+13230/1/202317/6/2026
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+32130/1/202317/6/2026
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
AnalizadaAlta (7.8)0.52%—Apple MacosFedoraproject FedoraNeovimVIM21/1/202324/9/2026
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
ModificadaMedia (6.5)0.66%—Neo4j Awesome Procedures ON Cyper14/1/202317/6/2026
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A path traversal vulnerability found in the apoc.export.* procedures of apoc plugins in Neo4j Graph database. The issue allows a malicious actor to potentially break out of the expected directory. The…
AnalizadaAlta (7.8)0.48%—Apple MacosFedoraproject FedoraNeovimVIM13/1/202324/9/2026
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
AnalizadaAlta (7.8)0.57%—Apple MacosNetapp HCI Compute NodeNeovimVIM+14/1/202324/9/2026
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
ModificadaMedia (6.1)0.51%—Neoxplora Project Neoxplora4/1/202317/6/2026
A vulnerability, which was classified as problematic, has been found in kkokko NeoXplora. Affected by this issue is some unknown functionality of the component Trainer Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is…
ModificadaCrítica (9.8)0.95%—IFM Moneo Qha210 FirmwareIFM Moneo Qha200 Firmware12/12/202217/6/2026
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.
ModificadaAlta (8.8)1.4%—Akeneo Product Information Management9/12/202217/6/2026
Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image. Akeneo PIM Community Edition after the versions aforementioned provides…
AnalizadaAlta (7.8)0.39%—NeovimVIM2/12/202224/9/2026
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
ModificadaAlta (7.4)0.75%—Velneo Vclient28/11/202217/6/2026
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.
AnalizadaAlta (7.8)0.45%—Debian LinuxNeovimVIMFedoraproject Fedora25/11/202224/9/2026
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
AnalizadaAlta (7.8)0.53%—NeovimVIMFedoraproject FedoraDebian Linux27/9/202224/9/2026
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
AnalizadaAlta (7.8)0.52%—NeovimVIMFedoraproject Fedora25/9/202224/9/2026
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
AnalizadaAlta (7.8)0.56%—NeovimVIMFedoraproject Fedora25/9/202224/9/2026
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
Orbitaley — Vulnerabilidades