Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

921 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.26%—KindeditorAISem-cms SemcmsAI23/9/202624/9/2026
A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross site scripting. The attack may be initiated remotely. The exploit has been published…
Pendiente de análisisMedia (6.5)0.29%—Io.netty Netty-codec-memcacheAI18/9/202625/9/2026
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can…
AplazadaMedia (5.5)0.86%—MemcachedAI14/9/202615/9/2026
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released…
Pendiente de análisisAlta (8.1)0.72%—Ansible Community.generalAIMemcachedAIPython-memcachedAI9/9/20269/9/2026
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached…
AplazadaMedia (5.4)0.29%—EMC EroomAI23/7/202623/7/2026
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
AplazadaAlta (8.5)0.36%—EMC EroomAI23/7/202623/7/2026
Contributor SQL Injection in eRoom <= 1.7.1 versions.
AplazadaMedia (6.8)0.16%—Samsung SemclipboardserviceAI10/7/202614/7/2026
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
Pendiente de análisisAlta (7.7)0.32%—Bosh Windows Stemcell BuilderAI9/7/20269/7/2026
Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
Pendiente de análisisAlta (8.5)0.15%—Bosh-ecosystem Bosh-windows-stemcell-builderAI9/7/20269/7/2026
Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected…
AplazadaMedia (6.3)0.15%—Sem-cms SemcmsAI9/6/202623/7/2026
SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.
AplazadaAlta (7.5)0.39%—Sem-cms SemcmsAI9/6/202623/7/2026
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
AnalizadaAlta (8.1)0.55%—Memcached20/5/202624/7/2026
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
ModificadaAlta (8.1)1.3%—Memcached20/5/202618/9/2026
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
AplazadaMedia (6.4)0.16%—Iobit Advanced SystemcareAI5/5/202617/6/2026
A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attacking locally is a requirement. This attack is characterized by high complexity. It is indicated that the exploitability is…
AplazadaMedia (6.4)0.19%—EMCAI19/4/202617/6/2026
The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly shortcode in all versions up to, and including, 4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaBaja (1.9)1.1%—0xkoda WiremcpAI11/3/202617/6/2026
A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js of the component Tshark CLI Command Handler. The manipulation results in os command injection. The attack needs to be approached locally. The exploit has been made…
AnalizadaBaja (2.1)0.38%—Sem-cms Semcms29/1/202617/6/2026
A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was…
ModificadaCrítica (9.8)0.98%—Sagemcom F@st 3686 Firmware12/1/20265/7/2026
Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.
AplazadaMedia (5.5)0.30%—Saiftheboss7 OnlinemcqexamAI28/12/202517/6/2026
A vulnerability was found in saiftheboss7 onlinemcqexam up to 0e56806132971e49721db3ef01868098c7b42ada. This vulnerability affects unknown code of the file /admin/quesadd.php. Performing manipulation of the argument ans1/ans2 results in sql injection. The attack is possible to be carried out remotely. The exploit has…
AplazadaMedia (5.8)0.20%—EMC EroomAI18/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Retrieve Embedded Sensitive Data.This issue affects eRoom: from n/a through <= 1.5.6.
AplazadaMedia (5.3)0.31%—EMC EroomAI25/10/202517/6/2026
The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all versions up to, and including, 1.5.6. This is due to the plugin exposing Zoom SDK secret keys in client-side JavaScript within the meeting view template. This makes…
AplazadaAlta (8.4)0.29%—EmcliAI13/10/202517/6/2026
EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Arbitrary Code Execution.
AnalizadaMedia (4.9)0.31%—Dell Poweredge R770 FirmwareDell Poweredge R670 FirmwareDell Poweredge R570 FirmwareDell Poweredge R470 Firmware+10825/9/202517/6/2026
Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
AnalizadaAlta (7.8)0.15%—Dell EMC Idrac Service Module21/8/202517/6/2026
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains a Buffer Access with Incorrect Length Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.
AnalizadaMedia (5.3)0.12%—Dell EMC Idrac Service Module21/8/202517/6/2026
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.