Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.55% | — | ARM Mbed OS | 20/11/2024 | 17/6/2026 | An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list of reports by reading a byte from an input stream. It then fetches the length of the first report, uses it to calculate the beginning of the second report, etc. In doing this, it… | |
| Modificada | Alta (7.5) | 0.48% | — | ARM Mbed | 20/11/2024 | 17/6/2026 | An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. This value is assumed to be greater than or equal to 3, but the software doesn't ensure that this is the case. Supplying a length less than 3 leads to a buffer… | |
| Modificada | Alta (7.5) | 0.38% | — | ARM Mbed | 20/11/2024 | 17/6/2026 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet data. A buffer is then allocated to contain the entire packet, the size of which is calculated as the length of the packet body determined… | |
| Modificada | Alta (7.5) | 0.46% | — | ARM Mbed | 20/11/2024 | 17/6/2026 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet header. A buffer is then allocated to contain the entire packet, the size of which is calculated as the length of the packet body determined… | |
| Modificada | Alta (7.5) | 0.36% | — | ARM Mbed | 20/11/2024 | 17/6/2026 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking up the identifying first byte and matching it against a table of possible lengths. The initial parsing function, hciTrSerialRxIncoming does not drop packets with… | |
| Aplazada | Media (6.5) | 0.30% | — | Joan Boluda Embed Documents ShortcodeAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joan Boluda Embed documents shortcode embed-documents-shortcode allows Stored XSS.This issue affects Embed documents shortcode: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.39% | — | Fayjur Pdf-embedder-fayAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fayjur Pdf Embedder Fay pdf-embedder-fay allows DOM-Based XSS.This issue affects Pdf Embedder Fay: from n/a through <= 1.10.1. | |
| Modificada | Alta (8.8) | 0.54% | — | Blrt WP Embed | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Blrt Blrt WP Embed blrt-wp-embed allows SQL Injection.This issue affects Blrt WP Embed: from n/a through <= 1.6.9. | |
| Aplazada | Media (6.4) | 0.32% | — | Davidartiss Code EmbedAI | 9/11/2024 | 17/6/2026 | The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web… | |
| Analizada | Alta (8.8) | 0.42% | — | Wpdeveloper Embedpress | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4. | |
| Analizada | Baja (3.7) | 0.47% | — | ARM Compiler FOR EmbeddedARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Clang | 31/10/2024 | 17/6/2026 | When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an… | |
| Aplazada | Crítica (10) | 1.1% | 💥 PoC | Ajar Productions Ajar IN5 EmbedAI | 29/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3. | |
| Modificada | Media (5.4) | 0.26% | — | Wpdeveloper Embedpress | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper EmbedPress embedpress allows Stored XSS.This issue affects EmbedPress: from n/a through <= 4.0.14. | |
| Analizada | Crítica (9.8) | 0.63% | — | Trustedfirmware Mbed TLS | 15/10/2024 | 17/6/2026 | Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair | |
| Aplazada | Media (6.1) | 0.38% | — | Embed Videos AND Respect PrivacyAI | 11/10/2024 | 17/6/2026 | The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.4) | 0.37% | — | Embed PDF ViewerAI | 9/10/2024 | 17/6/2026 | The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Analizada | Media (5.4) | 0.26% | — | Davidartiss Code Embed | 4/10/2024 | 17/6/2026 | The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions on who can utilize the functionality. This makes it possible for authenticated attackers, with contributor-level access… | |
| Analizada | Media (6.1) | 0.56% | — | Flowiseai EmbedFlowiseai Flowise | 25/9/2024 | 17/6/2026 | Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0. | |
| Analizada | Alta (7.7) | 1.3% | — | Rockwellautomation 2800c Optixpanel Compact FirmwareRockwellautomation 2800s Optixpanel Standard FirmwareRockwellautomation Embedded Edge Compute Module Firmware | 12/9/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges. | |
| Analizada | Alta (7.8) | 0.21% | — | Schneider-electric Vijeo DesignerSchneider-electric Vijeo Designer Embedded IN Ecostruxure Machine Expert | 11/9/2024 | 17/6/2026 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries. | |
| Modificada | Crítica (9.8) | 0.39% | — | Trustedfirmware Mbed TLS | 5/9/2024 | 17/6/2026 | An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() would incorrectly have… | |
| Analizada | Crítica (9.8) | 0.68% | — | Trustedfirmware Mbed TLS | 5/9/2024 | 17/6/2026 | An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This never happens in… | |
| Modificada | Media (5.1) | 0.24% | — | Trustedfirmware Mbed TLS | 5/9/2024 | 17/6/2026 | An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and… | |
| Analizada | Media (5.4) | 0.29% | — | Wpdeveloper Embedpress | 29/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.8. | |
| Analizada | Crítica (9.8) | 0.50% | — | Wpdeveloper Embedpress | 19/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9. |