Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.27% | ⚠ Explotación activa | Google Android | 28/6/2023 | 17/6/2026 | In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+1 | 23/6/2023 | 17/6/2026 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been… | |
| Analizada | Alta (8.8) | 23% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos | 23/6/2023 | 17/6/2026 | Se solucionó un problema de corrupción de memoria con una mejor gestión del estado. Este problema se solucionó en macOS Ventura 13.3, Safari 16.4, iOS 16.4 y iPadOS 16.4, iOS 15.7.7 y iPadOS 15.7.7. El procesamiento de contenido web puede provocar la ejecución de código arbitrario. Apple tiene conocimiento de un… | |
| Analizada | Alta (7.8) | 52% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Watchos | 23/6/2023 | 17/6/2026 | An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges.… | |
| Analizada | Alta (8.6) | 17% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 23/6/2023 | 17/6/2026 | The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been… | |
| Analizada | Alta (8.8) | 12% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+4 | 23/6/2023 | 17/6/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that… | |
| Analizada | Media (6.5) | 14% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 23/6/2023 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been… | |
| Analizada | Alta (8.8) | 29% | ⚠ Explotación activa | Papercut MFPapercut NG | 20/6/2023 | 17/6/2026 | Se ha identificado una vulnerabilidad de Cross-Site Request Forgery (CSRF) en PaperCut NG/MF que, en determinadas circunstancias, podría permitir a un atacante alterar la configuración de seguridad o ejecutar código arbitrario. Esto podría explotarse si el objetivo es un administrador con una sesión iniciada. Explotar… | |
| Analizada | Crítica (9.8) | 83% | ⚠ Explotación activa | Zyxel Nas326 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware | 19/6/2023 | 17/6/2026 | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands… | |
| Analizada | Alta (8.4) | 22% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+5 | 14/6/2023 | 17/6/2026 | Microsoft Streaming Service Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Analizada | Baja (3.9) | 14% | ⚠ Explotación activa | Vmware ToolsDebian LinuxFedoraproject Fedora | 13/6/2023 | 17/6/2026 | Un host ESXi totalmente comprometido puede obligar a VMware Tools a no poder autenticar las operaciones de host a invitado, lo que afecta la confidencialidad y la integridad de la máquina virtual invitada. | |
| Analizada | Crítica (9.8) | 86% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet Fortios | 13/6/2023 | 31/7/2026 | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may… | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Vmware Aria Operations FOR Networks | 7/6/2023 | 17/6/2026 | Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution. | |
| Analizada | Alta (8.8) | 42% | ⚠ Explotación activa💥 PoC | Tp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n Firmware | 7/6/2023 | 17/6/2026 | Se ha descubierto que TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, y TL-WR740N V1/V2 contienen una vulnerabilidad de inyección de comandos en el componente /userRpm/WlanNetworkRpm. | |
| Analizada | Alta (8.8) | 32% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject FedoraDebian LinuxApple Macos+2 | 5/6/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Progress Moveit CloudProgress Moveit Transfer | 2/6/2023 | 17/6/2026 | En Progress MOVEit Transfer antes de 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5) y 2023.0.1 (15.0.1), se ha encontrado una vulnerabilidad de inyección SQL en la aplicación web MOVEit Transfer que podría permitir que un atacante no autenticado obtenga acceso a la base de datos de MOVEit… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Igniterealtime Openfire | 26/5/2023 | 17/6/2026 | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an… | |
| Analizada | Crítica (9.8) | 88% | ⚠ Explotación activa💥 Exploit | Barracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+1 | 24/5/2023 | 17/6/2026 | A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Apache Rocketmq | 24/5/2023 | 17/6/2026 | For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update… | |
| Analizada | Crítica (9.8) | 29% | ⚠ Explotación activa | Zyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp100w Firmware+19 | 24/5/2023 | 17/6/2026 | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series… | |
| Analizada | Crítica (9.8) | 28% | ⚠ Explotación activa | Zyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp100w Firmware+19 | 24/5/2023 | 17/6/2026 | Una vulnerabilidad de desbordamiento de búfer en la función de notificación en las versiones de firmware de la serie Zyxel ATP 4.60 a 5.36 Parche 1, versiones de firmware de la serie USG FLEX 4.60 a 5.36 Parche 1, versiones de firmware USG FLEX 50(W) 4.60 a 5.36 Parche 1, USG20(W)- Las versiones de firmware VPN 4.60 a… | |
| Analizada | Alta (7.8) | 41% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows Server 2008Microsoft Windows Server 2012+1 | 9/5/2023 | 17/6/2026 | Win32k Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.2) | 85% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Media (4.4) | 2.6% | ⚠ Explotación activa | Samsung Android | 4/5/2023 | 17/6/2026 | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. |