Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
714 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.5% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Crítica (9.1) | 1.1% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical… | |
| Analizada | Alta (7.3) | 1.3% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Crítica (9.8) | 2.0% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may… | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root… | |
| Analizada | Alta (7.8) | 0.58% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root… | |
| Aplazada | Alta (7.1) | 0.18% | — | Igor Yavych Simple RatingAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Igor Yavych Simple Rating simple-rating allows Stored XSS.This issue affects Simple Rating: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.16% | — | Queeez Wp-postratings-cheaterAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in queeez WP-PostRatings Cheater wp-postratings-cheater allows Cross Site Request Forgery.This issue affects WP-PostRatings Cheater: from n/a through <= 1.5. | |
| Aplazada | Media (5.9) | 0.29% | — | Themelogger Contact Form 7 Star Rating With Font AwesomeAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating with font Awesome contact-form-7-star-rating-with-font-awersome allows Stored XSS.This issue affects Contact Form 7 Star Rating with font Awesome: from n/a through <= 1.3. | |
| Aplazada | Media (5.9) | 0.29% | — | Themelogger Contact Form 7 Star RatingAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating contact-form-7-star-rating allows Stored XSS.This issue affects Contact Form 7 Star Rating: from n/a through <= 1.10. | |
| Analizada | Media (5.3) | 0.16% | — | Broadcom Fabric Operating System | 15/2/2025 | 17/6/2026 | If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An… | |
| Analizada | Alta (8.6) | 0.45% | — | Broadcom Fabric Operating System | 15/2/2025 | 17/6/2026 | Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the… | |
| Analizada | Alta (7.5) | 0.23% | — | Dell Data Domain Operating System | 4/2/2025 | 17/6/2026 | Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote attacker could potentially exploit this vulnerability, leading to Information tampering. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Data Domain Operating System | 1/2/2025 | 17/6/2026 | Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege. | |
| Analizada | Media (4.9) | 0.39% | — | Dell Data Domain Operating System | 1/2/2025 | 17/6/2026 | Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer Overflow vulnerability in the RestAPI. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Alta (7.1) | 0.18% | — | Dell Data Domain Operating System | 1/2/2025 | 17/6/2026 | Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnerability to gain unauthorized overwrite of OS files stored on the server filesystem. Exploitation could lead to denial of service. | |
| Aplazada | Media (5.3) | 0.35% | — | Kamalkhan KK Star RatingsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in FeedbackWP kk Star Ratings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects kk Star Ratings: from n/a through 5.4.5. | |
| Aplazada | Alta (7.3) | 0.63% | — | Kamalkhan KK Star RatingsAI | 21/12/2024 | 17/6/2026 | The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes… | |
| Aplazada | Media (5.3) | 0.44% | — | Dash Labs YET Another Stars RatingAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Dash Labs Yet Another Stars Rating yet-another-stars-rating allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yet Another Stars Rating: from n/a through <= 3.4.3. | |
| Aplazada | Media (5.3) | 0.56% | — | Kamalkhan KK Star RatingsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in FeedbackWP kk Star Ratings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects kk Star Ratings: from n/a through 5.4.3. | |
| Aplazada | Media (5.4) | 0.52% | — | Noah Hearle Reviews AND Rating Google MY BusinessAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Noah Hearle, Design Extreme Reviews and Rating – Google My Business allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reviews and Rating – Google My Business: from n/a through 4.14. | |
| Analizada | Alta (7.5) | 0.59% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner(). | |
| Analizada | Alta (7.5) | 0.59% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner(). | |
| Analizada | Alta (7.5) | 0.59% | — | Openrobotics Robot Operating System | 6/12/2024 | 17/6/2026 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan(). |