Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Shopfiles Ebook Store | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions. | |
| Modificada | Crítica (9.8) | 0.53% | — | Facebook Hhvm | 10/5/2023 | 17/6/2026 | HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.172.1, 4.173.0 replaces TLS1.0 with TLS1.3. Applications that call… | |
| Modificada | Media (6.1) | 0.40% | — | Facebook Lexical | 29/4/2023 | 17/6/2026 | Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources. | |
| Modificada | Media (5.5) | 0.18% | — | HP Elite Dragonfly G3 FirmwareHP Dragonfly Folio G3 FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX Firmware+87 | 28/4/2023 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Media (6.1) | 0.47% | — | Bestwebsoft Facebook Button | 10/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.34… | |
| Modificada | Alta (8.8) | 0.35% | — | Bestwebsoft Facebook Button | 10/4/2023 | 16/6/2026 | A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the function fcbk_bttn_plgn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The… | |
| Modificada | Alta (7.5) | 1.6% | — | Facebook Zstandard | 31/3/2023 | 17/6/2026 | A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun. | |
| Modificada | Alta (8.8) | 4.5% | 💥 Exploit | Agilebio Electronic LAB Notebook | 6/3/2023 | 17/6/2026 | AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability. | |
| Modificada | Media (5.5) | 0.23% | — | Executablebooks Markdown-it-py | 23/2/2023 | 17/6/2026 | Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input. | |
| Modificada | Media (5.5) | 0.23% | — | Executablebooks Markdown-it-py | 22/2/2023 | 17/6/2026 | Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input. | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.31% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 1/2/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.24% | — | HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+177 | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.24% | — | HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+177 | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Alta (8.4) | 0.24% | — | HP Z1 G3 FirmwareHP Z2 Mini G3 FirmwareHP Z238 Microtower FirmwareHP Z240 SFF Firmware+71 | 12/12/2022 | 17/6/2026 | A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Crítica (9.8) | 1.3% | — | Facebook Redex | 11/11/2022 | 17/6/2026 | DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code execution during processing of a 3rd party Android APK file. | |
| Modificada | Crítica (9.8) | 0.99% | — | Facebook Hermes | 11/10/2022 | 17/6/2026 | An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence,… | |
| Modificada | Crítica (9.8) | 0.98% | — | Facebook Hermes | 11/10/2022 | 17/6/2026 | A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript.… | |
| Modificada | Crítica (9.8) | 0.98% | — | Facebook Hermes | 11/10/2022 | 17/6/2026 | An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence,… | |
| Modificada | Alta (7.5) | 0.87% | — | Facebook Hermes | 6/10/2022 | 17/6/2026 | It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0. | |
| Modificada | Crítica (9.8) | 1.2% | — | Viaviweb Ebook | 1/7/2022 | 17/6/2026 | SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books) 10 via the author_id parameter to api.php. | |
| Modificada | Media (4.3) | 1.1% | — | Jupyter Notebook | 14/6/2022 | 17/6/2026 | Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the notebook server with `ContentsManager.allow_hidden = False` only prevented listing the contents of hidden directories, not accessing individual hidden files or files in hidden… | |
| Modificada | Media (4.8) | 0.60% | — | Facebook-wall-and-social-integration Project Facebook-wall-and-social-integration | 13/6/2022 | 17/6/2026 | The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them back in attributes, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.8) | 0.48% | — | Fujitsu Lifebook A3510 FirmwareFujitsu Lifebook U9310 FirmwareFujitsu Lifebook U7511 FirmwareFujitsu Lifebook U7411 Firmware+8 | 4/5/2022 | 17/6/2026 | An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U7311), v2.33 (U9311), v2.23 (E5510), v2.19 (U7510/U7410), v2.13 (U7310), and v1.09 (E459/E449). The… |