Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.47% | — | Php-date-formatterAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Aplazada | Crítica (9) | 0.64% | — | Veeam UpdaterAI | 5/2/2025 | 17/6/2026 | A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate. | |
| Aplazada | Media (6.5) | 0.30% | — | Freebsd EtcupdateAI | 30/1/2025 | 17/6/2026 | When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted visibility, such as /etc/master.passwd. An… | |
| Aplazada | Alta (7.1) | 0.22% | — | UpdatecliAI | 24/1/2025 | 17/6/2026 | Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source configured with basic auth credentials,… | |
| Analizada | Alta (7.4) | 0.68% | — | Microsoft Edge Update | 17/1/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 0.45% | — | Microsoft Autoupdate | 14/1/2025 | 17/6/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Modificada | Alta (7.5) | 2.3% | — | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+14 | 14/1/2025 | 30/6/2026 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification… | |
| Modificada | Alta (7.5) | 8.8% | 💥 PoC | Samba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+18 | 14/1/2025 | 21/9/2026 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. | |
| Analizada | Alta (7.8) | 0.19% | — | Dell Update Package Framework | 7/1/2025 | 17/6/2026 | Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker. | |
| Aplazada | Alta (7.1) | 0.26% | — | Irshad A Khan Services Updates FOR CustomersAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad A.Khan Services updates for customers service-updates-for-customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through <= 1.0. | |
| Analizada | Media (6.1) | 0.48% | — | Androidbubbles WP Datepicker | 24/12/2024 | 17/6/2026 | The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.5) | 0.47% | — | Webchunky Order Delivery Pickup Location Date TimeAI | 18/12/2024 | 17/6/2026 | Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-location-date-time-free-version allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery & Pickup Location Date Time: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.41% | — | Jaytesh Barange Posts Date RangesAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jaytesh Barange Posts Date Ranges posts-date-ranges allows Reflected XSS.This issue affects Posts Date Ranges: from n/a through <= 2.2. | |
| Aplazada | Media (5.3) | 0.50% | — | Apasionados Comment Blacklist UpdaterAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in apasionados Comment Blacklist Updater comment-blacklist-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comment Blacklist Updater: from n/a through <= 1.1.0. | |
| Analizada | Crítica (9.8) | 1.3% | — | Microsoft Update Catalog | 12/12/2024 | 17/6/2026 | Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Dock Hd22q Firmware Update UtilityDell Dock Wd19 Firmware Update UtilityDell Dock Wd22tb4 Firmware Update Utility | 11/12/2024 | 17/6/2026 | Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Seventhqueen Sweet DateAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects Sweet Date: from n/a through <= 3.7.3. | |
| Aplazada | Media (5.4) | 0.39% | — | Prasadkirpekar WP Meta AND Date RemoverAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in prasadkirpekar WP Meta and Date Remover wp-meta-and-date-remover allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Meta and Date Remover: from n/a through <= 2.3.0. | |
| Aplazada | Crítica (9.8) | 23% | 💥 Exploit | WP Umbrella Update Backup Restore AND MonitoringAI | 8/12/2024 | 17/6/2026 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the… | |
| Aplazada | Media (6.1) | 0.46% | — | Parsi DateAI | 26/11/2024 | 17/6/2026 | The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… | |
| Analizada | Media (4.4) | 0.21% | — | Dell Intel Management Engine Firmware Update Utility | 22/11/2024 | 17/6/2026 | Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this… | |
| Aplazada | Alta (7.1) | 0.18% | — | Mikeage Hebrew DateAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mikeage Hebrew Date hebrewdates allows Stored XSS.This issue affects Hebrew Date: from n/a through <= 2.1.0. | |
| Aplazada | Alta (7.1) | 0.21% | — | Akira1891 Update-notificationsAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in akira1891 UPDATE NOTIFICATIONS update-notifications allows Stored XSS.This issue affects UPDATE NOTIFICATIONS: from n/a through <= 0.3.4. | |
| Aplazada | Alta (7.1) | 0.19% | — | Intel Server Board S2600st Family BiosAIIntel Firmware Update SoftwareAI | 13/11/2024 | 17/6/2026 | Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to potentially enable escalation of privilege via local access. |