Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.21% | — | Wpmudev Hummingbird | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1. | |
| Aplazada | Media (5.3) | 0.36% | — | Weblizar Coming SoonAI | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3. | |
| Modificada | Alta (7.8) | 0.46% | — | Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming | 8/8/2024 | 17/6/2026 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Media (6.3) | 0.48% | — | Nats ServerAINats Streaming ServerAI | 11/7/2024 | 17/6/2026 | NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied… | |
| Modificada | Alta (8.2) | 0.17% | — | Dell Edge Gateway 5000 FirmwareDell Edge Gateway 5100 FirmwareDell Edge Gateway 5200 FirmwareDell Edge Gateway 3200 Firmware+2 | 10/7/2024 | 17/6/2026 | Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege. | |
| Modificada | Media (6.7) | 0.15% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+384 | 2/7/2024 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges | |
| Modificada | Media (6.1) | 0.80% | 💥 PoC | Moodle Virtual Programming LAB | 24/6/2024 | 17/6/2026 | Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js. | |
| Modificada | Media (5.5) | 0.20% | — | Nvidia Virtual GPUNvidia Cloud Gaming | 13/6/2024 | 17/6/2026 | NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure. | |
| Modificada | Media (5.5) | 0.19% | — | Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming | 13/6/2024 | 17/6/2026 | NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service. | |
| Modificada | Alta (7.8) | 0.24% | — | Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming | 13/6/2024 | 17/6/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering. | |
| Modificada | Alta (7.8) | 0.27% | — | Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming | 13/6/2024 | 17/6/2026 | NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Modificada | Alta (7.8) | 0.23% | — | Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming | 13/6/2024 | 17/6/2026 | NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering. | |
| Modificada | Media (5.5) | 0.15% | — | Nvidia Virtual GPUNvidia Cloud Gaming | 13/6/2024 | 17/6/2026 | NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin. | |
| Modificada | Alta (7.8) | 0.12% | — | Nvidia Virtual GPUNvidia Cloud Gaming | 13/6/2024 | 17/6/2026 | NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service. | |
| Modificada | Alta (7.8) | 0.23% | — | Nvidia Virtual GPUNvidia Cloud Gaming | 13/6/2024 | 17/6/2026 | NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service. | |
| Modificada | Media (5.3) | 0.28% | — | Incsub Hummingbird | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.7.3. | |
| Modificada | Media (5.4) | 0.44% | — | Webfactoryltd Minimal Coming Soon & Maintenance Mode | 8/6/2024 | 17/6/2026 | The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (3.7) | 0.34% | — | Wpdevart Coming Soon AND Maintenance ModeAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming soon and Maintenance mode: from n/a through 3.7.3. | |
| Aplazada | Media (5.1) | 1.9% | — | Huashi Private Cloud CDN Live Streaming Acceleration ServerAI | 23/5/2024 | 17/6/2026 | A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an unknown function of the file /manager/ipconfig_new.php. The manipulation of the argument dev leads to os command injection. It is possible to launch the attack… | |
| Aplazada | Media (6.7) | 0.17% | — | Endurance Gaming ModeAI | 16/5/2024 | 17/6/2026 | Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.2) | 0.26% | — | Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+15 | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software… | |
| Aplazada | Media (6.3) | 0.77% | — | Wargaming World OF WarshipsAI | 14/5/2024 | 17/6/2026 | WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the… | |
| Aplazada | Media (4.1) | 0.36% | — | Mingsoft MS BasicAI | 7/5/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier. | |
| Analizada | Media (6.6) | 1.2% | — | Qnap Media Streaming Add-on | 3/5/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and… | |
| Analizada | Crítica (9.8) | 0.54% | — | Qnap Media Streaming Add-on | 26/4/2024 | 17/6/2026 | An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 (… |