Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

344 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.66%—Brandbugle7/6/202217/6/2026
A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is some unknown functionality of the file /main.php. The manipulation leads to sql injection. The attack may be launched remotely.
ModificadaCrítica (9.8)1.9%—Grandcom Dynweb19/5/202217/6/2026
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify…
ModificadaAlta (7.5)1.9%—Random Password Generator Project Random Password Generator18/5/202217/6/2026
The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.
ModificadaMedia (5.4)0.77%—Jenkins Random String Parameter17/5/202217/6/2026
Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaAlta (8.1)83%💥 ExploitBrandexponents Tatsu25/4/202217/6/2026
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.…
ModificadaMedia (4.8)0.60%—Codeasily Grand Flagallery28/2/202217/6/2026
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.5)1.2%—Quadlayers Perfect Brands FOR Woocommerce18/2/202217/6/2026
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.
ModificadaMedia (4.3)0.63%—Quadlayers Perfect Brands FOR Woocommerce18/2/202217/6/2026
The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4).
ModificadaMedia (4.8)4.4%—Buffercode Random Banner18/1/202217/6/2026
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This…
ModificadaCrítica (9.8)1.2%—Nanorand Project Nanorand27/12/202117/6/2026
An issue was discovered in the nanorand crate before 0.6.1 for Rust. There can be multiple mutable references to the same object because the TlsWyRand Deref implementation dereferences a raw pointer.
ModificadaAlta (8.8)2.0%—Grandstream Ht801 Firmware28/10/202117/6/2026
An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host.
ModificadaAlta (8.8)7.4%💥 PoCGrandstream Ht801 Firmware28/10/202117/6/2026
Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device.…
ModificadaCrítica (9.8)1.4%—Brandy Project Brandy11/10/202117/6/2026
A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.
ModificadaAlta (8.6)1.1%—Acuitybrands Nlight Eclypse System Controller Firmware17/9/202117/6/2026
nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controllers utilize an encrypted channel to secure SensorViewTM configuration and…
ModificadaMedia (6.1)0.90%—Videowhisper 2way Videocalls AND Random Chat16/8/202117/6/2026
The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.2.7.
ModificadaMedia (5.4)0.62%—Thememason Popular Brand Icons - Simple Icons2/8/202117/6/2026
The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an…
ModificadaAlta (7.8)0.21%—Intel Brand Verification Tool17/6/202117/6/2026
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.35%—Intel Brand Verification ToolFedoraproject FedoraIntel Pentium Processors FirmwareIntel Celeron Processors Firmware+39/6/202117/6/2026
Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
ModificadaAlta (8.8)1.3%—Luvion Grand Elite 3 Connect Firmware2/4/202117/6/2026
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.
ModificadaCrítica (9.8)1.8%—Grandstream Grp2612 FirmwareGrandstream Grp2612p FirmwareGrandstream Grp2612w FirmwareGrandstream Grp2613 Firmware+329/3/202117/6/2026
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
ModificadaAlta (7.2)2.4%—Grandstream Grp2612 FirmwareGrandstream Grp2612p FirmwareGrandstream Grp2612w FirmwareGrandstream Grp2613 Firmware+329/3/202117/6/2026
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
ModificadaCrítica (9.8)1.2%—Rand Core Project Rand Core18/2/202117/6/2026
An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.
ModificadaAlta (7.8)0.43%—Autorand Project Autorand26/1/202117/6/2026
An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized memory can be dropped when a panic occurs, leading to memory corruption.
ModificadaCrítica (9.8)1.5%—Nanorand Project Nanorand31/12/202017/6/2026
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.
ModificadaCrítica (9.8)1.6%—Rust-random Rand14/9/202019/8/2026
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
Orbitaley — Vulnerabilidades