Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.29%—Hulumi DriftAI31/8/202631/8/2026
@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.
AplazadaAlta (7.8)0.72%—Driftregion Iso14229AI14/6/202610/8/2026
driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-byte 0x27…
AplazadaMedia (6.4)0.26%—DriftAI19/2/202617/6/2026
The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web…
AplazadaMedia (5.9)0.22%—Wpdrift Landing-pages-and-domain-aliasesAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdrift.no Landing pages and Domain aliases for WordPress landing-pages-and-domain-aliases allows Stored XSS.This issue affects Landing pages and Domain aliases for WordPress: from n/a through <= 0.8.
ModificadaBaja (2.4)0.35%—Lenovo Thinkpad T490 (20nx) FirmwareLenovo Thinkpad T490 (20qx) FirmwareLenovo Thinkpad T490 (20rx) FirmwareLenovo Thinkpad T490s (20nx) Firmware+61/9/202017/6/2026
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx…
ModificadaMedia (6.8)0.31%—Lenovo Thinkpad A275 FirmwareLenovo Thinkpad A285 FirmwareLenovo Thinkpad A475 FirmwareLenovo Thinkpad A485 Firmware+41/9/202017/6/2026
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.
ModificadaAlta (7.1)0.31%—Redhat RHQ Mongo DB Drift ServerRedhat Jboss Operations Network4/11/201916/6/2026
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.
ModificadaMedia (5.4)0.27%—Drifty Ionic View19/10/201417/6/2026
The Ionic View (aka com.ionic.viewapp) application 0.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.