Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.42% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX FirmwareHP Elite X2 1013 G3 Firmware+183 | 16/2/2022 | 7/10/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.45% | — | HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+183 | 16/2/2022 | 7/10/2026 | A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware. | |
| Modificada | Alta (8.8) | 0.44% | — | HP 260 G3 Desktop Mini PC FirmwareHP Elitedesk 800 35W G4 Desktop Mini PC FirmwareHP Elitedesk 800 65W G4 Desktop Mini PC FirmwareHP Elitedesk 800 95W G4 Desktop Mini PC Firmware+183 | 16/2/2022 | 7/10/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. | |
| Modificada | Crítica (9.1) | 17% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. | |
| Modificada | Crítica (9.8) | 1.2% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Qnap QVR EliteQnap QVR GuardQnap QVR PRO | 14/1/2022 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR… | |
| Modificada | Crítica (9.8) | 1.3% | — | Qnap QVR EliteQnap QVR GuardQnap QVR PRO | 14/1/2022 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR… | |
| Modificada | Crítica (9.8) | 1.3% | — | Qnap QVR EliteQnap QVR GuardQnap QVR PRO | 14/1/2022 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR… | |
| Modificada | Crítica (9.8) | 1.3% | — | Qnap QVR EliteQnap QVR GuardQnap QVR PRO | 14/1/2022 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR… | |
| Modificada | Crítica (9.8) | 1.3% | — | Qnap QVR EliteQnap QVR GuardQnap QVR PRO | 14/1/2022 | 17/6/2026 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR… | |
| Modificada | Media (6.1) | 0.91% | — | Pixelite Events Manager | 1/12/2021 | 17/6/2026 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues | |
| Modificada | Alta (7.2) | 1.5% | — | Pixelite Events Manager | 1/12/2021 | 17/6/2026 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection | |
| Modificada | Alta (8.8) | 0.67% | — | Delitestudio Push Notifications FOR Wordpress | 24/11/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page. | |
| Modificada | Alta (8.8) | 1.3% | — | Luvion Grand Elite 3 Connect Firmware | 2/4/2021 | 17/6/2026 | An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Media (6.7) | 0.46% | — | HP Elite X2 1012 G1 FirmwareHP Elite X2 1012 G2 FirmwareHP Elitebook 1030 G1 FirmwareHP Elitebook 1040 G4 Firmware+10 | 12/8/2020 | 17/6/2026 | The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file. | |
| Modificada | Media (6) | 0.55% | — | Synaptics Vfs75xx FirmwareLenovo Thinkpad 25 FirmwareLenovo Thankpad A475 FirmwareLenovo Thankpad A485 Firmware+129 | 22/7/2020 | 17/6/2026 | Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table. | |
| Modificada | Media (6.8) | 0.60% | — | HP Elitedesk 800 G5 DM FirmwareHP Elitedesk 800 G5 SFF FirmwareHP Elitedesk 800 G5 TWR FirmwareHP Eliteone 800 G5 AIO Firmware+29 | 31/1/2020 | 17/6/2026 | A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slots with specialized hardware and software tools to modify UEFI code in memory. This affects HP Intel-based Business PCs… | |
| Modificada | Alta (7.8) | 0.39% | — | Dell Latitude E6430 FirmwareHP Elitebook 850 G1 Firmware | 30/1/2020 | 17/6/2026 | The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls operate on SMRAM memory locations, which allows local users to bypass the Secure Boot protection… | |
| Modificada | Alta (7.2) | 2.0% | — | HP 260 G1 DM FirmwareHP 280 PRO G1 FirmwareHP 285 G2 FirmwareHP 340 G3 Firmware+98 | 5/11/2019 | 17/6/2026 | A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management… |