Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.18% | — | Intel Server Board S2600st Family Bios AND Firmware UpdateAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path for the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.1) | 0.49% | — | Tychesoftwares Product Delivery Date FOR WoocommerceAI | 13/11/2024 | 17/6/2026 | The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.8.0. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.7) | 0.13% | — | SAP Netweaver JavaAISAP Software Update ManagerAI | 12/11/2024 | 17/6/2026 | In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to… | |
| Aplazada | Alta (7) | 0.18% | — | Macrovision Update ServiceAI | 8/11/2024 | 17/6/2026 | An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in the Elefant Update Service during the repair or update process. When using the repair function, the service queries the server for a list of files and their… | |
| Aplazada | Alta (7.8) | 2.0% | — | Elefant Software UpdaterAI | 8/11/2024 | 17/6/2026 | An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service which is running as… | |
| Modificada | Crítica (9.8) | 0.41% | — | Androidbubbles WP Datepicker | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Fahad Mahmood WP Datepicker wp-datepicker.This issue affects WP Datepicker: from n/a through <= 2.1.1. | |
| Aplazada | Media (5.3) | 0.52% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Product Delivery Date for WooCommerce – Lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.2. | |
| Aplazada | Alta (8.7) | 0.41% | — | Validatejs Validate.jsAI | 26/10/2024 | 17/6/2026 | Validate.js provides a declarative way of validating javascript objects. All versions as of 30 November 2020 contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are available. | |
| Aplazada | Alta (8.7) | 0.45% | — | Validatejs Validate.jsAI | 26/10/2024 | 17/6/2026 | Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are available. | |
| Analizada | Alta (8.7) | 0.51% | — | Validatejs Validate.js | 26/10/2024 | 17/6/2026 | Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available. | |
| Modificada | Alta (8.8) | 0.44% | — | Hasanmovahed Duplicate Title Validate | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hasan movahed Duplicate Title Validate duplicate-title-validate allows Blind SQL Injection.This issue affects Duplicate Title Validate: from n/a through <= 1.0. | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+11 | 15/10/2024 | 17/6/2026 | A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in… | |
| Modificada | Media (4.4) | 0.39% | — | Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux EUS+10 | 9/10/2024 | 7/8/2026 | A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by… | |
| Modificada | Media (4.8) | 0.31% | — | Androidbubbles WP Datepicker | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Datepicker wp-datepicker allows Stored XSS.This issue affects WP Datepicker: from n/a through <= 2.1.1. | |
| Analizada | Media (6.1) | 0.39% | — | Tychesoftwares Product Delivery Date FOR Woocommerce | 4/10/2024 | 17/6/2026 | The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (8.2) | 0.51% | — | Theupdateframework Go-tufAI | 1/10/2024 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegations in the order "A" then "B" then "C" but it may incorrectly trace the… | |
| Aplazada | Alta (8.3) | 0.12% | — | Intel Seamless Firmware UpdatesAI | 16/9/2024 | 17/6/2026 | Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access. | |
| Aplazada | Crítica (9.1) | 0.65% | 💥 PoC | No-ip Dynamic Update ClientAI | 12/9/2024 | 17/6/2026 | No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior. | |
| Analizada | Alta (7.8) | 0.48% | — | Microsoft Autoupdate | 10/9/2024 | 10/8/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+342 | 28/8/2024 | 17/6/2026 | Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | |
| Modificada | Media (5.3) | 0.48% | — | Coffee2code NO Update NAG | 12/8/2024 | 17/6/2026 | The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Analizada | Alta (7.5) | 0.38% | — | Dell Alienware UpdateDell Command UpdateDell Update | 6/8/2024 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (5.4) | 0.69% | 💥 PoC | Datex-soft E-staff | 25/7/2024 | 17/6/2026 | A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation. | |
| Aplazada | Alta (7.1) | 0.35% | — | Obtaininfotech Multisite Content Copier UpdaterAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Infotech Multisite Content Copier/Updater allows Reflected XSS.This issue affects Multisite Content Copier/Updater: from n/a through 1.5.0. | |
| Modificada | Crítica (9.8) | 1.0% | — | Datenverwurstungszentrale Shariff Wrapper | 20/6/2024 | 17/6/2026 | The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This… |