Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.47%—Php-date-formatterAI5/2/202517/6/2026
A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
AplazadaCrítica (9)0.64%—Veeam UpdaterAI5/2/202517/6/2026
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.
AplazadaMedia (6.5)0.30%—Freebsd EtcupdateAI30/1/202517/6/2026
When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted visibility, such as /etc/master.passwd. An…
AplazadaAlta (7.1)0.22%—UpdatecliAI24/1/202517/6/2026
Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source configured with basic auth credentials,…
AnalizadaAlta (7.4)0.68%—Microsoft Edge Update17/1/202517/6/2026
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)0.45%—Microsoft Autoupdate14/1/202517/6/2026
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
ModificadaAlta (7.5)4.7%—Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+1614/1/202530/6/2026
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
ModificadaAlta (7.5)2.3%—Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+1414/1/202530/6/2026
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification…
ModificadaAlta (7.5)8.8%💥 PoCSamba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+1814/1/202521/9/2026
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
AnalizadaAlta (7.8)0.19%—Dell Update Package Framework7/1/202517/6/2026
Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker.
AplazadaAlta (7.1)0.26%—Irshad A Khan Services Updates FOR CustomersAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad A.Khan Services updates for customers service-updates-for-customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through <= 1.0.
AnalizadaMedia (6.1)0.48%—Androidbubbles WP Datepicker24/12/202417/6/2026
The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (6.5)0.47%—Webchunky Order Delivery Pickup Location Date TimeAI18/12/202417/6/2026
Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-location-date-time-free-version allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery & Pickup Location Date Time: from n/a through <= 1.1.0.
AplazadaAlta (7.1)0.41%—Jaytesh Barange Posts Date RangesAI16/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jaytesh Barange Posts Date Ranges posts-date-ranges allows Reflected XSS.This issue affects Posts Date Ranges: from n/a through <= 2.2.
AplazadaMedia (5.3)0.50%—Apasionados Comment Blacklist UpdaterAI13/12/202417/6/2026
Missing Authorization vulnerability in apasionados Comment Blacklist Updater comment-blacklist-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comment Blacklist Updater: from n/a through <= 1.1.0.
AnalizadaCrítica (9.8)1.3%—Microsoft Update Catalog12/12/202417/6/2026
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
AnalizadaMedia (6.7)0.17%—Dell Dock Hd22q Firmware Update UtilityDell Dock Wd19 Firmware Update UtilityDell Dock Wd22tb4 Firmware Update Utility11/12/202417/6/2026
Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AplazadaCrítica (9.8)0.78%—Seventhqueen Sweet DateAI9/12/202417/6/2026
Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects Sweet Date: from n/a through <= 3.7.3.
AplazadaMedia (5.4)0.39%—Prasadkirpekar WP Meta AND Date RemoverAI9/12/202417/6/2026
Missing Authorization vulnerability in prasadkirpekar WP Meta and Date Remover wp-meta-and-date-remover allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Meta and Date Remover: from n/a through <= 2.3.0.
AplazadaCrítica (9.8)23%💥 ExploitWP Umbrella Update Backup Restore AND MonitoringAI8/12/202417/6/2026
The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the…
AplazadaMedia (6.1)0.46%—Parsi DateAI26/11/202417/6/2026
The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can…
AnalizadaMedia (4.4)0.21%—Dell Intel Management Engine Firmware Update Utility22/11/202417/6/2026
Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this…
AplazadaAlta (7.1)0.18%—Mikeage Hebrew DateAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in mikeage Hebrew Date hebrewdates allows Stored XSS.This issue affects Hebrew Date: from n/a through <= 2.1.0.
AplazadaAlta (7.1)0.21%—Akira1891 Update-notificationsAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in akira1891 UPDATE NOTIFICATIONS update-notifications allows Stored XSS.This issue affects UPDATE NOTIFICATIONS: from n/a through <= 0.3.4.
AplazadaAlta (7.1)0.19%—Intel Server Board S2600st Family BiosAIIntel Firmware Update SoftwareAI13/11/202417/6/2026
Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to potentially enable escalation of privilege via local access.
Orbitaley — Vulnerabilidades