Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Ipushpull Live Updates From Excel | 31/10/2023 | 17/6/2026 | The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpull_page' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (7.1) | 0.12% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions. | |
| Modificada | Alta (7.8) | 0.12% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges. | |
| Modificada | Media (6.3) | 0.10% | — | Lenovo System Update PluginLenovo Hardware Scan PluginLenovo Hardware Scan Addin | 27/10/2023 | 17/6/2026 | A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files. | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64+18 | 23/10/2023 | 17/6/2026 | The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use… | |
| Modificada | Alta (7.5) | 0.54% | — | HP Thinupdate | 13/10/2023 | 17/6/2026 | A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability. | |
| Modificada | Alta (8.8) | 0.27% | — | Dineshkarki Block Plugin Update | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki Block Plugin Update plugin <= 3.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Iwebss Update Theme AND Plugins From ZIP File | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 versions. | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Alta (7.5) | 32% | 💥 Exploit | Myprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts | 20/9/2023 | 17/6/2026 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. | |
| Modificada | Alta (7.8) | 0.23% | — | Corecode Macupdater | 20/9/2023 | 17/6/2026 | An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files. | |
| Modificada | Media (5.9) | 1.6% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+18 | 18/9/2023 | 14/7/2026 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the… | |
| Modificada | Media (6.5) | 1.7% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+23 | 18/9/2023 | 17/6/2026 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a… | |
| Modificada | Alta (7.8) | 0.66% | — | Microsoft Windows Defender Security Intelligence Updates | 12/9/2023 | 17/6/2026 | Windows Defender Attack Surface Reduction Security Feature Bypass | |
| Modificada | Alta (7.8) | 0.38% | 💥 PoC | Foxconn Live Update Utility | 11/9/2023 | 17/6/2026 | An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges. | |
| Modificada | Alta (7.8) | 0.24% | — | Redhat Subscription-managerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+16 | 23/8/2023 | 17/6/2026 | A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a… | |
| Modificada | Media (4.8) | 0.37% | — | Marcosteinbrecher WP Browserupdate | 17/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Steinbrecher WP BrowserUpdate plugin <= 4.5 versions. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Server Firmware Update Utility | 11/8/2023 | 17/6/2026 | Unquoted search path in the software installer for the System Firmware Update Utility (SysFwUpdt) for some Intel(R) Server Boards and Intel(R) Server Systems Based on Intel(R) 621A Chipset before version 16.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.22% | — | Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions. | |
| Modificada | Alta (7.3) | 0.19% | — | Dell Alienware UpdateDell Command UpdateDell Update | 23/6/2023 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation. | |
| Modificada | Alta (7.1) | 0.18% | — | Dell Alienware UpdateDell Command UpdateDell Update | 23/6/2023 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS). | |
| Modificada | Media (6.7) | 0.16% | — | Intel ONE Boot Flash Update | 10/5/2023 | 17/6/2026 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel ONE Boot Flash Update | 10/5/2023 | 17/6/2026 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access | |
| Modificada | Alta (7.8) | 0.15% | — | Intel NUC Hdmi Firmware Update Tool | 10/5/2023 | 17/6/2026 | Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.20% | — | Intel NUC Hdmi Firmware Update Tool | 10/5/2023 | 17/6/2026 | Uncontrolled search path for the Intel(R) HDMI Firmware Update tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |