Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

1334 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7)0.12%—ControlflashAI1/9/20261/9/2026
A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at…
AplazadaMedia (5.3)0.16%—FlashattentionAI13/7/202617/9/2026
FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-plant a symlink in the predictable cache…
AplazadaMedia (5.8)0.31%—Flash AND Html5 VideoAI26/6/202626/6/2026
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
AplazadaMedia (6.5)0.53%—FlashmqAI10/6/202623/7/2026
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of their write buffer and triggering an internal safe-guard exception. This exception was in a path that was not catchable, and therefore causes a…
Pendiente de análisisAlta (8.7)0.35%—Purestorage Flasharray PurityAI9/6/202623/7/2026
A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.
Pendiente de análisisAlta (8.6)0.35%—Purestorage Flasharray PurityAI9/6/202623/7/2026
A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges.
AplazadaAlta (8.6)0.18%—Flash Slideshow Maker ProfessionalAI25/5/202624/7/2026
Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog…
AplazadaAlta (7.3)0.40%—Flash-attentionAI11/5/202617/6/2026
The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python eval() function as a Hydra configuration resolver under the name eval. This allows configuration files to execute…
AplazadaAlta (7.3)0.37%—Flash-attentionAI11/5/202617/6/2026
The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechanism. The load_checkpoint() function in checkpoint.py and the checkpoint loading code in eval.py use torch.load() without…
AplazadaMedia (6.5)0.65%—FlashmqAI8/5/202617/6/2026
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with retained publish permission can crash the FlashMQ broker when both set_retained_message_defer_timeout and set_retained_message_defer_timeout_spread are configured to non-default values, resulting in…
Pendiente de análisisMedia (6.9)0.38%—Purestorage Flasharray PurityAI14/4/202617/6/2026
Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured.
Pendiente de análisisAlta (8.5)0.38%—Purestorage FlashbladeAI14/4/202617/6/2026
A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.
AplazadaAlta (7.1)0.12%—Joshuae1974 Flash Video PlayerAI20/3/202617/6/2026
Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Player: from n/a through 5.0.4.
Pendiente de análisisAlta (8.7)0.11%—Intel Uefi FlashucacmsmmAI10/3/202617/6/2026
Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially occur via local access when attack…
AplazadaAlta (8.1)0.56%—Magentech FlashmartAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech FlashMart flashmart allows PHP Local File Inclusion.This issue affects FlashMart: from n/a through <= 2.0.15.
AplazadaMedia (6.5)0.35%—Tufat FlashcardAI7/1/202630/9/2026
The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'source' attribute of the 'flashcard' shortcode. This makes it possible for authenticated attackers, with contributor level access and above, to read the contents of arbitrary files on the server, which…
ModificadaAlta (8.1)0.53%—Ancorathemes Theflash18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes The Flash theflash allows PHP Local File Inclusion.This issue affects The Flash: from n/a through <= 1.15.
AplazadaAlta (8.5)0.14%—USB Flash Drives ControlAI17/12/202517/6/2026
USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to inject malicious executables and escalate…
AnalizadaMedia (6.6)0.10%—Netun Helpflash IOT Firmware17/12/202517/6/2026
The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical access can activate OTA mode (8-second…
AplazadaMedia (4.3)0.13%—Flashyapp WP Flashy Marketing AutomationAI9/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Flashyapp WP Flashy Marketing Automation wp-flashy-marketing-automation allows Cross Site Request Forgery.This issue affects WP Flashy Marketing Automation: from n/a through <= 2.0.8.
AplazadaMedia (5.4)0.10%—Intel ONE Boot Flash UpdateAI11/11/202517/6/2026
Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of…
AplazadaMedia (5.4)0.12%—Intel ONE Boot Flash UpdateAI11/11/202517/6/2026
Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.…
AnalizadaMedia (4.3)0.34%—Flashmq24/10/202517/6/2026
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. When not sent to a client, these are then not released upon (eventual) session expiration. Version 1.23.2 fixes the issue.
AplazadaAlta (7.2)0.22%—HP Sure StartAIHP BiosAIIntel Flash DescriptorAI7/10/202517/6/2026
A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is releasing BIOS updates to mitigate the potential…
AplazadaMedia (6.5)0.17%—Vincent Boiardt Easy Flash EmbedAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Boiardt Easy Flash Embed easy-flash-embed allows Stored XSS.This issue affects Easy Flash Embed: from n/a through <= 1.0.