Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

474 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)17%—Bravenewcode Wptouch9/1/202317/6/2026
The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
ModificadaAlta (7.5)47%💥 ExploitAveva Intouch Access Anywhere23/12/202217/6/2026
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
ModificadaMedia (4.7)0.26%💥 PoCLenovo Elan Miniport Touchpad Driver7/11/202217/6/2026
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.
ModificadaAlta (7.8)0.47%💥 PoCUbports Ubuntu Touch9/9/202217/6/2026
UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The described attack cannot be executed as demonstrated.
ModificadaMedia (4.8)0.61%—Mtouch Quiz Project Mtouch Quiz8/8/202217/6/2026
The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.5)0.96%—Couchbase Server21/7/202217/6/2026
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
ModificadaMedia (5.9)0.63%—Couchbase Server15/7/202217/6/2026
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
ModificadaMedia (5.3)1.0%—Couchbase Server12/7/202217/6/2026
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.
ModificadaAlta (7.5)1.2%—Couchbase Server12/7/202217/6/2026
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection to determine the TLS port number, using SCRAM-SHA instead.
ModificadaAlta (7.5)0.89%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1511/7/202217/6/2026
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.
ModificadaAlta (7.5)0.89%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1511/7/202217/6/2026
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.
ModificadaAlta (7.8)0.78%—Fujielectric Monitouch V-sft16/6/202217/6/2026
Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
ModificadaAlta (7.8)0.78%—Fujielectric Monitouch V-sft16/6/202217/6/2026
Out-of-bounds write vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.
ModificadaMedia (4.9)0.81%—Couchbase Server14/6/202217/6/2026
An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network.
ModificadaCrítica (9.1)1.3%—Couchbase Server14/6/202217/6/2026
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
ModificadaAlta (7.5)1.1%—Couchbase Server14/6/202217/6/2026
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.
ModificadaAlta (7.5)1.1%—Couchbase Server13/6/202217/6/2026
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.
ModificadaAlta (8.8)0.96%—Couchbase Server13/6/202217/6/2026
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
ModificadaAlta (7.5)0.93%—Couchbase Server13/6/202217/6/2026
Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
ModificadaAlta (7.5)1.1%—Couchbase Server13/6/202217/6/2026
An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.
ModificadaAlta (7.5)1.0%—Couchbase Server13/6/202217/6/2026
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
ModificadaAlta (7.5)1.2%—Couchbase Server13/6/202217/6/2026
An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.
ModificadaMedia (6.5)0.73%—Couchbase Server13/6/202217/6/2026
Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
ModificadaCrítica (9.8)0.81%—Couchbase Sync Gateway10/6/202217/6/2026
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin credentials…
ModificadaAlta (8.8)0.99%—Deltacontrols Entelitouch Firmware2/6/202217/6/2026
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request.
Orbitaley — Vulnerabilidades