Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.51% | — | Theupdateframework Go-tufAI | 1/10/2024 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the… | |
| Aplazada | Alta (8.3) | 0.12% | — | Intel Seamless Firmware UpdatesAI | 16/9/2024 | 17/6/2026 | Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access. | |
| Aplazada | Crítica (9.1) | 0.65% | 💥 PoC | No-ip Dynamic Update ClientAI | 12/9/2024 | 17/6/2026 | No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior. | |
| Analizada | Alta (7.8) | 0.48% | — | Microsoft Autoupdate | 10/9/2024 | 10/8/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+342 | 28/8/2024 | 17/6/2026 | Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | |
| Modificada | Media (5.3) | 0.48% | — | Coffee2code NO Update NAG | 12/8/2024 | 17/6/2026 | The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Analizada | Alta (7.5) | 0.38% | — | Dell Alienware UpdateDell Command UpdateDell Update | 6/8/2024 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Aplazada | Alta (7.1) | 0.35% | — | Obtaininfotech Multisite Content Copier UpdaterAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Infotech Multisite Content Copier/Updater allows Reflected XSS.This issue affects Multisite Content Copier/Updater: from n/a through 1.5.0. | |
| Aplazada | Media (5.9) | 0.20% | — | Akbr UpdateAI | 17/6/2024 | 17/6/2026 | akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js. | |
| Modificada | Alta (8.1) | 2.1% | 💥 PoC | Redhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux EUSRedhat Enterprise Linux TUS+1 | 12/6/2024 | 17/6/2026 | A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is encrypted using the target principal key directly. For user principals, this key… | |
| Aplazada | Media (4.3) | 0.37% | — | Minoji MJ Update HistoryAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Minoji MJ Update History.This issue affects MJ Update History: from n/a through 1.0.4. | |
| Modificada | Alta (7.8) | 0.15% | — | Google Updater | 7/6/2024 | 17/6/2026 | Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium security severity: High) | |
| Modificada | Alta (7.8) | 0.16% | 💥 PoC | Google Updater | 7/6/2024 | 17/6/2026 | Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High) | |
| Modificada | Media (5.9) | 0.53% | — | Clusterlabs BoothRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+4 | 6/6/2024 | 17/6/2026 | A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server. | |
| Analizada | Media (4.9) | 0.25% | — | Dell Openmanage Enterprise Update Manager | 8/5/2024 | 17/6/2026 | Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to… | |
| Aplazada | Crítica (9.8) | 0.67% | — | Helloshop DeliveryorderautoupdateAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function. | |
| Modificada | Alta (7.1) | 1.0% | — | Fedoraproject SssdRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64+19 | 18/4/2024 | 17/6/2026 | A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. | |
| Aplazada | Alta (7.1) | 0.35% | — | Minoji MJ Update HistoryAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Minoji MJ Update History allows Reflected XSS.This issue affects MJ Update History: from n/a through 1.0.4. | |
| Analizada | Media (6.5) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3… | |
| Analizada | Media (6.5) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong… | |
| Analizada | Media (6.5) | 1.0% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch.… | |
| Analizada | Media (5.3) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use… | |
| Analizada | Alta (8.8) | 1.3% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users… | |
| Aplazada | Media (6.7) | 0.18% | — | Lenovo Bios Update Tool DriverAI | 5/4/2024 | 17/6/2026 | A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code. | |
| Analizada | Alta (7.8) | 0.99% | — | Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+4 | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability |