Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.37% | — | Project Team Tmall Demo | 15/7/2024 | 17/6/2026 | An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information. | |
| Analizada | Media (4.9) | 0.34% | — | Project Team Tmall Demo | 15/7/2024 | 17/6/2026 | Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage. | |
| Analizada | Media (5.3) | 0.47% | — | Linlinjava Litemall | 2/7/2024 | 17/6/2026 | A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. The manipulation of the argument goodsId/goodsSn/name leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Media (6.7) | 0.15% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+384 | 2/7/2024 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Aplazada | Media (5.3) | 0.33% | — | Smallweight AvueAI | 11/6/2024 | 17/6/2026 | A vulnerability classified as problematic was found in smallweigit Avue up to 3.4.4. Affected by this vulnerability is an unknown functionality of the component avueUeditor. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.8) | 0.18% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. | |
| Analizada | Media (6.8) | 0.17% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. | |
| Aplazada | Alta (7.2) | 0.56% | — | Askey 5G NR Small CellAI | 27/5/2024 | 17/6/2026 | ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with administrator privilege to execute arbitrary system commands on the remote server. | |
| Aplazada | Media (5.3) | 0.36% | — | Prasidhdamalla Honeypot FOR WP CommentAI | 17/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Prasidhda Malla Honeypot for WP Comment.This issue affects Honeypot for WP Comment: from n/a through 2.2.3. | |
| Analizada | Crítica (9.8) | 0.92% | — | Phpgurukul Small CRM | 12/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is some unknown functionality of the component Registration Page. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Alta (8.8) | 1.3% | 💥 PoC | Phpgurukul Small CRM | 12/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Small CRM 3.0. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (4.4) | 0.18% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+264 | 10/4/2024 | 17/6/2026 | Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Aplazada | Media (6.3) | 0.83% | 💥 PoC | Mini-tmallAI | 1/3/2024 | 17/6/2026 | A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown processing of the file ?r=tmall/admin/user/1/1. The manipulation of the argument orderBy leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (4.9) | 0.49% | — | Dell Precision 3430 Tower FirmwareDell Precision 3431 Tower FirmwareDell Precision 3630 Tower FirmwareDell Precision 5820 Tower Firmware+169 | 1/3/2024 | 17/6/2026 | Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function. | |
| Analizada | Alta (7.2) | 0.72% | — | Linlinjava Litemall | 27/2/2024 | 17/6/2026 | SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component. | |
| Analizada | Media (6.4) | 0.28% | — | HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+23 | 14/2/2024 | 17/6/2026 | Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. | |
| Analizada | Media (6.4) | 0.28% | — | HP Elite Mini 600 G9 FirmwareHP Elite Mini 800 G9 FirmwareHP Elite SFF 600 G9 FirmwareHP Elite SFF 800 G9 Firmware+23 | 14/2/2024 | 17/6/2026 | Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities. | |
| Modificada | Media (6.1) | 0.33% | — | Prasidhdamalla Honeypot FOR WP Comment | 12/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Honeypot for WP Comment allows Reflected XSS.This issue affects Honeypot for WP Comment: from n/a through 2.2.3. | |
| Modificada | Media (4.4) | 0.16% | — | Dell Optiplex 3000 Micro FirmwareDell Optiplex 3000 Small Form Factor FirmwareDell Optiplex 3000 Tower FirmwareDell Optiplex 5000 Micro Firmware+287 | 6/2/2024 | 17/6/2026 | Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Exrick Xmall | 6/2/2024 | 17/6/2026 | xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. | |
| Modificada | Crítica (9.8) | 0.55% | — | Fuyanglipengjun Wetong Mall | 12/1/2024 | 17/6/2026 | A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file platform-shop\src\main\resources\com\platform\dao\OrderDao.xml. The manipulation of the argument sidx/order leads to sql injection. The associated identifier of this… | |
| Modificada | Crítica (9.8) | 0.94% | — | Csdeshang Dsmall | 11/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of the file application/home/controller/MemberAuth.php. The manipulation of the argument file_name leads to path traversal: '../filedir'. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.56% | — | Csdeshang Dsmall | 11/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php of the component Image URL Handler. The manipulation leads to improper access controls. The attack can be launched… | |
| Modificada | Alta (7.5) | 2.2% | — | Csdeshang Dsmall | 11/1/2024 | 17/6/2026 | A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php of the component HTTP GET Request Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been… |