Skip to content
Toggle Navigation
ISO/IEC 27001
Introducción a ISO 27001
Requisitos Normativos
ISO 27001 – GAP Analysis (Tool)
Todos el contenido
Ciberseguridad
Introducción a la ciberseguridad
Defensa de sistemas informáticos
Amenazas y tendencias
Eventos de ciberseguridad
Glosario
Todos los artículos
Vulnerabilidades CVE
Desarrollo seguro (SDLC)
Desarrollo de software seguro
Normativa y Leyes
Leyes de protección de datos
Agencias nacionales de ciberseguridad
Contacto
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Filtrar por severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
Filtrar
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2025-7098
2025-07-06
MEDIUM
5.6
A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function…
CVE-2025-7097
2025-07-06
HIGH
8.1
A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some…
CVE-2025-7096
2025-07-06
HIGH
8.1
A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the…
CVE-2025-7095
2025-07-06
LOW
3.7
A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of…
CVE-2025-7094
2025-07-06
HIGH
8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. Affected by this issue is the…
CVE-2025-7093
2025-07-06
HIGH
8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. Affected by this vulnerability is the…
CVE-2025-7092
2025-07-06
HIGH
8.8
A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. This vulnerability affects the function formWlanSetupWPS of…
CVE-2025-7091
2025-07-06
HIGH
8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. Affected is the function formWlanMP of…
CVE-2025-7090
2025-07-06
HIGH
8.8
A vulnerability, which was classified as critical, has been found in Belkin F9K1122 1.00.33. Affected by this issue is the…
CVE-2025-7089
2025-07-06
HIGH
8.8
A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. This issue affects the function formWanTcpipSetup of the…
CVE-2025-53376
2025-07-07
N/A
0.0
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An…
CVE-2025-53375
2025-07-07
N/A
0.0
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An…
CVE-2025-53374
2025-07-07
N/A
0.0
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An…
CVE-2025-53373
2025-07-07
N/A
0.0
Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled server…
CVE-2025-52492
2025-07-07
N/A
0.0
A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded…
CVE-2025-48367
2025-07-07
HIGH
7.5
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors,…
CVE-2025-53169
2025-07-07
HIGH
7.6
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this…
CVE-2025-47202
2025-07-07
N/A
0.0
In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,…
CVE-2025-45479
2025-07-07
N/A
0.0
Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content…
CVE-2025-45065
2025-07-07
N/A
0.0
employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php…
CVE-2025-43933
2025-07-07
N/A
0.0
fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset…
CVE-2025-43932
2025-07-07
N/A
0.0
JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset…
CVE-2025-43931
2025-07-07
N/A
0.0
flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset…
CVE-2025-3262
2025-07-07
MEDIUM
5.3
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability…
CVE-2025-3044
2025-07-07
MEDIUM
5.3
A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when…
CVE-2025-32023
2025-07-07
HIGH
7.0
Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19,…
CVE-2025-26780
2025-07-07
N/A
0.0
An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of…
CVE-2023-51232
2025-07-07
N/A
0.0
Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive information via crafted request to the…
CVE-2025-7133
2025-07-07
MEDIUM
4.3
A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown…
CVE-2025-7132
2025-07-07
HIGH
7.3
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been rated as critical. Affected by this issue…
CVE-2025-6811
2025-07-07
CRITICAL
9.8
Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code…
CVE-2025-6810
2025-07-07
CRITICAL
9.8
Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code…
CVE-2025-7056
2025-07-07
MEDIUM
6.3
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UrlShortener Extension…
CVE-2025-6807
2025-07-07
MEDIUM
5.3
Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-6806
2025-07-07
HIGH
8.2
Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected…
CVE-2025-6805
2025-07-07
HIGH
8.2
Marvell QConvergeConsole deleteEventLogFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected…
CVE-2025-6804
2025-07-07
HIGH
7.5
Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-6803
2025-07-07
HIGH
7.5
Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-6802
2025-07-07
CRITICAL
9.8
Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…
CVE-2025-6801
2025-07-07
HIGH
8.2
Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected…
CVE-2025-6800
2025-07-07
HIGH
7.5
Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-6799
2025-07-07
HIGH
7.5
Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-6798
2025-07-07
HIGH
8.2
Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected…
CVE-2025-6797
2025-07-07
HIGH
7.5
Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-6796
2025-07-07
HIGH
7.5
Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-6795
2025-07-07
MEDIUM
5.3
Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations…
CVE-2025-6794
2025-07-07
CRITICAL
9.8
Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…
CVE-2025-6793
2025-07-07
CRITICAL
9.4
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability allows remote attackers to delete arbitrary…
CVE-2025-6714
2025-07-07
HIGH
7.5
MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB…
CVE-2025-6713
2025-07-07
HIGH
7.7
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling…
« Anterior
Página 193 de 3484
Siguiente »
Page load link
Go to Top