Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
344 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.66% | — | Brandbugle | 7/6/2022 | 17/6/2026 | A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is some unknown functionality of the file /main.php. The manipulation leads to sql injection. The attack may be launched remotely. | |
| Modificada | Crítica (9.8) | 1.9% | — | Grandcom Dynweb | 19/5/2022 | 17/6/2026 | GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify… | |
| Modificada | Alta (7.5) | 1.9% | — | Random Password Generator Project Random Password Generator | 18/5/2022 | 17/6/2026 | The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction. | |
| Modificada | Media (5.4) | 0.77% | — | Jenkins Random String Parameter | 17/5/2022 | 17/6/2026 | Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.1) | 83% | 💥 Exploit | Brandexponents Tatsu | 25/4/2022 | 17/6/2026 | The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.… | |
| Modificada | Media (4.8) | 0.60% | — | Codeasily Grand Flagallery | 28/2/2022 | 17/6/2026 | The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.5) | 1.2% | — | Quadlayers Perfect Brands FOR Woocommerce | 18/2/2022 | 17/6/2026 | The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure. | |
| Modificada | Media (4.3) | 0.63% | — | Quadlayers Perfect Brands FOR Woocommerce | 18/2/2022 | 17/6/2026 | The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4). | |
| Modificada | Media (4.8) | 4.4% | — | Buffercode Random Banner | 18/1/2022 | 17/6/2026 | The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This… | |
| Modificada | Crítica (9.8) | 1.2% | — | Nanorand Project Nanorand | 27/12/2021 | 17/6/2026 | An issue was discovered in the nanorand crate before 0.6.1 for Rust. There can be multiple mutable references to the same object because the TlsWyRand Deref implementation dereferences a raw pointer. | |
| Modificada | Alta (8.8) | 2.0% | — | Grandstream Ht801 Firmware | 28/10/2021 | 17/6/2026 | An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host. | |
| Modificada | Alta (8.8) | 7.4% | 💥 PoC | Grandstream Ht801 Firmware | 28/10/2021 | 17/6/2026 | Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device.… | |
| Modificada | Crítica (9.8) | 1.4% | — | Brandy Project Brandy | 11/10/2021 | 17/6/2026 | A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function. | |
| Modificada | Alta (8.6) | 1.1% | — | Acuitybrands Nlight Eclypse System Controller Firmware | 17/9/2021 | 17/6/2026 | nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controllers utilize an encrypted channel to secure SensorViewTM configuration and… | |
| Modificada | Media (6.1) | 0.90% | — | Videowhisper 2way Videocalls AND Random Chat | 16/8/2021 | 17/6/2026 | The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.2.7. | |
| Modificada | Media (5.4) | 0.62% | — | Thememason Popular Brand Icons - Simple Icons | 2/8/2021 | 17/6/2026 | The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an… | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Brand Verification Tool | 17/6/2021 | 17/6/2026 | Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.35% | — | Intel Brand Verification ToolFedoraproject FedoraIntel Pentium Processors FirmwareIntel Celeron Processors Firmware+3 | 9/6/2021 | 17/6/2026 | Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Alta (8.8) | 1.3% | — | Luvion Grand Elite 3 Connect Firmware | 2/4/2021 | 17/6/2026 | An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model. | |
| Modificada | Crítica (9.8) | 1.8% | — | Grandstream Grp2612 FirmwareGrandstream Grp2612p FirmwareGrandstream Grp2612w FirmwareGrandstream Grp2613 Firmware+3 | 29/3/2021 | 17/6/2026 | Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. | |
| Modificada | Alta (7.2) | 2.4% | — | Grandstream Grp2612 FirmwareGrandstream Grp2612p FirmwareGrandstream Grp2612w FirmwareGrandstream Grp2613 Firmware+3 | 29/3/2021 | 17/6/2026 | Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface. | |
| Modificada | Crítica (9.8) | 1.2% | — | Rand Core Project Rand Core | 18/2/2021 | 17/6/2026 | An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data. | |
| Modificada | Alta (7.8) | 0.43% | — | Autorand Project Autorand | 26/1/2021 | 17/6/2026 | An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized memory can be dropped when a panic occurs, leading to memory corruption. | |
| Modificada | Crítica (9.8) | 1.5% | — | Nanorand Project Nanorand | 31/12/2020 | 17/6/2026 | An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled. | |
| Modificada | Crítica (9.8) | 1.6% | — | Rust-random Rand | 14/9/2020 | 19/8/2026 | An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints. |