Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1028 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code. See SEL Service Bulletin… | |
| Modificada | Media (5.4) | 0.44% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject and execute arbitrary script code.See SEL Service Bulletin… | |
| Modificada | Alta (8.8) | 0.36% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface allows Authentication Bypass. See SEL Service Bulletin dated 2022-11-15 for more details. | |
| Modificada | Media (4.2) | 0.25% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Certificate Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote unauthenticated attacker to conduct a man-in-the-middle (MitM) attack. See SEL Service Bulletin dated 2022-11-15 for more details. | |
| Modificada | Media (6.5) | 0.47% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more details. | |
| Modificada | Alta (8.8) | 1.1% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See SEL Service Bulletin dated 2022-11-15 for more details. | |
| Modificada | Alta (8.8) | 1.1% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | An Improper Input Validation vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to execute arbitrary code. See SEL Service Bulletin dated 2022-11-15 for more details. | |
| Modificada | Media (5.3) | 0.50% | — | Selinc Sel-2241 Rtac Module FirmwareSelinc Sel-3350 FirmwareSelinc Sel-3505 FirmwareSelinc Sel-3505-3 Firmware+6 | 10/5/2023 | 17/6/2026 | A Channel Accessible by Non-Endpoint vulnerability in the Schweitzer Engineering Laboratories SEL Real-Time Automation Controller (RTAC) could allow a remote attacker to perform a man-in-the-middle (MiTM) that could result in denial of service. See the ACSELERATOR RTAC SEL-5033 Software instruction manual date code… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Idnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter | 12/4/2023 | 17/6/2026 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(). | |
| Modificada | Baja (3.3) | 0.19% | — | ARM Avalon Android Gralloc ModuleARM Bifrost Android Gralloc ModuleARM Valhall Android Gralloc Module | 11/4/2023 | 17/6/2026 | An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0. | |
| Modificada | Alta (7.5) | 0.94% | — | Siemens Siprotec 5 6md85 FirmwareSiemens Siprotec 5 6md86 FirmwareSiemens Siprotec 5 6md89 FirmwareSiemens Siprotec 5 6mu85 Firmware+35 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD89 (CP300) (All versions >= V7.80 < V9.64), SIPROTEC 5 6MU85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7KE85 (CP300) (All versions >= V7.80… | |
| Modificada | Crítica (9.8) | 1.2% | — | Myprestamodules Frequently Asked Questions Page | 31/3/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component. | |
| Modificada | Crítica (9.8) | 0.60% | — | Atm-consulting Dolibarr Module Quicksupplierprice | 20/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version… | |
| Modificada | Alta (7.8) | 1.3% | — | Trustedcomputinggroup Trusted Platform ModuleMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+8 | 28/2/2023 | 17/6/2026 | An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it… | |
| Modificada | Media (5.5) | 5.6% | — | Trustedcomputinggroup Trusted Platform ModuleMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+8 | 28/2/2023 | 17/6/2026 | An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM. | |
| Modificada | Alta (8.8) | 2.4% | — | Netmodule Router Software | 16/2/2023 | 17/6/2026 | The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web root directory, authenticated users could gain remote command execution with elevated privileges. This issue affects NSRW: from 4.3.0.0… | |
| Modificada | Alta (8.8) | 29% | 💥 PoC | Netmodule Router Software | 16/2/2023 | 17/6/2026 | NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0… | |
| Modificada | Alta (7.8) | 0.22% | — | Suse Linux Enterprise Module FOR SAP ApplicationsOpensuse LeapSuse Linux Enterprise Server | 15/2/2023 | 17/6/2026 | An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects:… | |
| Modificada | Media (5.4) | 0.56% | — | Simplesamlphp-module-openidprovider | 17/1/2023 | 16/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in simplesamlphp simplesamlphp-module-openidprovider up to 0.8.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file templates/trust.tpl.php. The manipulation of the argument StateID leads to cross site… | |
| Modificada | Crítica (9.8) | 1.5% | — | Global-modules-path Project Global-modules-path | 13/1/2023 | 17/6/2026 | Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function. | |
| Modificada | Media (6.1) | 0.51% | — | Simplesamlphp Information Cards Module | 9/1/2023 | 16/6/2026 | A vulnerability was found in Information Cards Module on simpleSAMLphp and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.0 is able to address this issue. The identifier of the patch is… | |
| Modificada | Media (5.3) | 0.63% | — | Paysafe Barzahlen Payment Module PHP SDK | 8/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be… | |
| Modificada | Media (6.1) | 0.64% | — | Simplesamlphp-module-openid | 1/1/2023 | 16/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-module-openid. Affected is an unknown function of the file templates/consumer.php of the component OpenID Handler. The manipulation of the argument AuthState leads to cross site scripting. It is… | |
| Modificada | Media (6.1) | 0.95% | — | Openmrs Admin UI Module | 27/12/2022 | 17/6/2026 | A vulnerability was found in OpenMRS Admin UI Module up to 1.4.x. It has been rated as problematic. This issue affects some unknown processing of the file omod/src/main/webapp/pages/metadata/privileges/privilege.gsp of the component Manage Privilege Page. The manipulation leads to cross site scripting. The attack may… |