Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Winwar WP Email Capture | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Winwar WP Email Capture | 2/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | |
| Modificada | Media (6.5) | 0.62% | — | Oracle Clinical Remote Data Capture | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture.… | |
| Modificada | Media (5.4) | 0.39% | — | Bigfork Silverstripe Form Capture | 3/4/2023 | 17/6/2026 | Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users. Starting in version 0.2.0 and prior to versions 1.0.2, 1.1.0, 2.2.5, and 3.1.1, improper escaping when presenting stored form submissions allowed for an attacker to perform a Cross-Site Scripting attack.… | |
| Modificada | Media (6.1) | 0.52% | — | Esri Arcgis Quickcapture | 15/11/2022 | 17/6/2026 | An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain. | |
| Modificada | Media (5.5) | 1.7% | — | Bentley Contextcapture Viewer | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley ContextCapture 10.18.0.232. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing… | |
| Modificada | Media (5.5) | 1.7% | — | Bentley Contextcapture Viewer | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley ContextCapture 10.18.0.232. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing… | |
| Modificada | Baja (3.3) | 0.22% | — | Samsung Smart Capture | 8/12/2021 | 17/6/2026 | Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission. | |
| Modificada | Media (6.1) | 0.90% | — | Wiseagent Wise Agent Capture Forms | 10/9/2021 | 17/6/2026 | The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/WiseAgentCaptureForm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0. | |
| Modificada | Media (5.5) | 0.28% | — | Samsung Capture | 9/9/2021 | 17/6/2026 | An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak. | |
| Modificada | Media (6.5) | 1.3% | — | Pcapture Project Pcapture | 7/9/2021 | 17/6/2026 | pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter and without adequate permissions. This is important because the capture filters can effectively… | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Avermedia Capture Card | 11/8/2021 | 17/6/2026 | Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 2.0% | — | IBM Infosphere Data ReplicationIBM Infosphere Change Data Capture | 16/7/2021 | 17/6/2026 | IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834 | |
| Modificada | Alta (7.4) | 18% | — | OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+29 | 25/3/2021 | 17/6/2026 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict… | |
| Modificada | Media (5.9) | 64% | — | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Crítica (9.8) | 1.3% | — | IBM Qradar Network Packet Capture | 10/6/2020 | 17/6/2026 | IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803. | |
| Modificada | Alta (7.5) | 76% | — | Huntcctv Dvr-04ch FirmwareHuntcctv Dvr-04nc FirmwareHuntcctv Dvr-08ch FirmwareHuntcctv Dvr-08nc Firmware+16 | 30/10/2019 | 16/6/2026 | Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration. | |
| Modificada | Crítica (9.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Cp5525 FirmwareHP Color Laserjet Enterprise M553 FirmwareHP Color Laserjet Enterprise M552 Firmware+139 | 11/4/2019 | 17/6/2026 | HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise printers have an insufficient solution bundle signature validation that potentially allows execution of arbitrary code. | |
| Modificada | Crítica (9.8) | 2.6% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Cp5525 FirmwareHP Color Laserjet Enterprise Flow MFP M681f FirmwareHP Color Laserjet Enterprise Flow MFP M681z Firmware+134 | 27/3/2019 | 17/6/2026 | In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code. | |
| Modificada | Crítica (9.8) | 1.0% | — | Abbyy Flexicapture | 10/2/2019 | 17/6/2026 | Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter. | |
| Modificada | Alta (8.8) | 0.46% | — | Abbyy Flexicapture | 9/7/2018 | 17/6/2026 | Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Verification, Web Scanning, Web Capture, Monitoring and Administration, and Login. | |
| Modificada | Crítica (9.8) | 1.1% | — | Abbyy Flexicapture | 9/7/2018 | 17/6/2026 | The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCaptureTmsSts2 parameter. | |
| Modificada | Media (5.9) | 0.85% | — | IBM Tealeaf Customer Experience ON Cloud Network Capture Add-on | 8/2/2017 | 17/6/2026 | IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the TLS certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Modificada | Baja (2.7) | 0.53% | — | HP Capture AND Route Software | 27/4/2015 | 17/6/2026 | Unspecified vulnerability in HP Capture and Route Software (HPCR) 1.3 before Patch 7, 1.3 FP1 before Patch 1, and 1.4 before Patch 1 allows remote authenticated users to obtain sensitive information via unknown vectors. | |
| Modificada | Baja (2.1) | 0.54% | — | EMC Captiva Capture | 14/2/2015 | 17/6/2026 | The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 places a cleartext InputAccel (IA) SQL password in a DAL log file, which allows local users to obtain sensitive information by reading a file. |