Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.33%—Avalon23 Products Filter FOR WoocommerceAI24/6/202625/6/2026
The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and including, 1.1.6. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (notably 'title' and…
AplazadaMedia (5.5)0.31%—Rubylouvre AvalonAI15/6/202624/7/2026
A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype attributes. It is possible to launch the…
ModificadaMedia (5.5)0.18%—ARM Avalon GPU Kernel DriverARM Valhall GPU Kernel Driver2/6/202317/6/2026
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.
ModificadaMedia (5.5)0.18%—ARM Avalon GPU Kernel DriverARM Bifrost GPU Kernel DriverARM Midgard GPU Kernel DriverARM Valhall GPU Kernel Driver2/6/202317/6/2026
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhall r19p0 through r42p0 before r43p0, and Arm's GPU Architecture…
ModificadaBaja (3.3)0.19%—ARM Avalon Android Gralloc ModuleARM Bifrost Android Gralloc ModuleARM Valhall Android Gralloc Module11/4/202317/6/2026
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
ModificadaBaja (3.3)0.22%—ARM Avalon GPU Kernel DriverARM Valhall GPU Kernel Driver11/4/202317/6/2026
An issue was discovered in the Arm Mali Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.
ModificadaBaja (3.3)0.22%—ARM Avalon GPU Kernel DriverARM Valhall GPU Kernel Driver6/4/202317/6/2026
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.
ModificadaAlta (8.8)0.70%—ARM Avalon GPU Kernel DriverARM Valhall GPU Kernel Driver8/3/202317/6/2026
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r39p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
ModificadaAlta (8.8)2.7%—ARM Avalon GPU Kernel DriverARM Bifrost GPU Kernel DriverARM Midgard GPU Kernel DriverARM Valhall GPU Kernel Driver6/3/202317/6/2026
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r0p0 through r32p0, Bifrost r0p0 through r41p0 before r42p0, Valhall r19p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
ModificadaAlta (7.5)0.76%—Canaan Avalon Asic Miner Firmware1/9/202217/6/2026
An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a crafted POST request.
ModificadaAlta (8.2)0.37%—Philips Intellivue MP2 FirmwarePhilips Intellivue X2 FirmwarePhilips Intellivue Mp30 FirmwarePhilips Intellivue Mp50 Firmware+145/6/201817/6/2026
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo"…
ModificadaMedia (5.3)0.42%—Philips Intellivue MP2 FirmwarePhilips Intellivue X2 FirmwarePhilips Intellivue Mp30 FirmwarePhilips Intellivue Mp50 Firmware+145/6/201817/6/2026
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an…
ModificadaAlta (8.3)0.39%—Philips Intellivue MP2 FirmwarePhilips Intellivue X2 FirmwarePhilips Intellivue Mp30 FirmwarePhilips Intellivue Mp50 Firmware+145/6/201817/6/2026
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an…
ModificadaAlta (7.5)2.3%—Avalonnet News Manager19/5/200816/6/2026
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the read_xml_include parameter.
ModificadaMedia (6.4)1.2%—Avalon LTD Maxtrade1/5/200616/6/2026
SQL injection vulnerability in pocategories.php in MaxTrade 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categori and (2) stranica parameters.