Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.21%—Wpmudev Hummingbird26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1.
AplazadaMedia (5.3)0.36%—Weblizar Coming SoonAI13/8/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3.
ModificadaAlta (7.8)0.46%—Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming8/8/202417/6/2026
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
AplazadaMedia (6.3)0.48%—Nats ServerAINats Streaming ServerAI11/7/202417/6/2026
NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied…
ModificadaAlta (8.2)0.17%—Dell Edge Gateway 5000 FirmwareDell Edge Gateway 5100 FirmwareDell Edge Gateway 5200 FirmwareDell Edge Gateway 3200 Firmware+210/7/202417/6/2026
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
ModificadaMedia (6.7)0.15%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+3842/7/202417/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
ModificadaMedia (6.1)0.80%💥 PoCMoodle Virtual Programming LAB24/6/202417/6/2026
Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.
ModificadaMedia (5.5)0.20%—Nvidia Virtual GPUNvidia Cloud Gaming13/6/202417/6/2026
NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.
ModificadaMedia (5.5)0.19%—Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming13/6/202417/6/2026
NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.
ModificadaAlta (7.8)0.24%—Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming13/6/202417/6/2026
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.
ModificadaAlta (7.8)0.27%—Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming13/6/202417/6/2026
NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
ModificadaAlta (7.8)0.23%—Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming13/6/202417/6/2026
NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.
ModificadaMedia (5.5)0.15%—Nvidia Virtual GPUNvidia Cloud Gaming13/6/202417/6/2026
NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin.
ModificadaAlta (7.8)0.12%—Nvidia Virtual GPUNvidia Cloud Gaming13/6/202417/6/2026
NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.
ModificadaAlta (7.8)0.23%—Nvidia Virtual GPUNvidia Cloud Gaming13/6/202417/6/2026
NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.
ModificadaMedia (5.3)0.28%—Incsub Hummingbird9/6/202417/6/2026
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.7.3.
ModificadaMedia (5.4)0.44%—Webfactoryltd Minimal Coming Soon & Maintenance Mode8/6/202417/6/2026
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with…
AplazadaBaja (3.7)0.34%—Wpdevart Coming Soon AND Maintenance ModeAI4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming soon and Maintenance mode: from n/a through 3.7.3.
AplazadaMedia (5.1)1.9%—Huashi Private Cloud CDN Live Streaming Acceleration ServerAI23/5/202417/6/2026
A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been classified as critical. Affected is an unknown function of the file /manager/ipconfig_new.php. The manipulation of the argument dev leads to os command injection. It is possible to launch the attack…
AplazadaMedia (6.7)0.17%—Endurance Gaming ModeAI16/5/202417/6/2026
Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.2)0.26%—Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+1514/5/202417/6/2026
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software…
AplazadaMedia (6.3)0.77%—Wargaming World OF WarshipsAI14/5/202417/6/2026
WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the…
AplazadaMedia (4.1)0.36%—Mingsoft MS BasicAI7/5/202417/6/2026
Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.
AnalizadaMedia (6.6)1.2%—Qnap Media Streaming Add-on3/5/202417/6/2026
An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and…
AnalizadaCrítica (9.8)0.54%—Qnap Media Streaming Add-on26/4/202417/6/2026
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 (…
Orbitaley — Vulnerabilidades