Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.16% | — | Redhat Jboss A-mqRedhat Jboss MiddlewareRedhat Openshift Container Platform | 27/9/2023 | 17/6/2026 | A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker. | |
| Modificada | Media (5.5) | 0.25% | — | Redhat Jboss A-mqRedhat Jboss MiddlewareRedhat Openshift Container Platform | 27/9/2023 | 17/6/2026 | A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions. | |
| Modificada | Alta (7.5) | 2.7% | — | Redhat UndertowRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM LinuxoneRedhat Openshift Container Platform FOR Power+3 | 27/9/2023 | 17/6/2026 | A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by… | |
| Modificada | Alta (8.1) | 1.4% | — | QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+8 | 20/9/2023 | 4/8/2026 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and… | |
| Modificada | Alta (7.2) | 1.2% | — | Bosch RTS Vlink Virtual Matrix | 18/9/2023 | 17/6/2026 | A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface. | |
| Modificada | Alta (7.5) | 1.8% | — | Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+12 | 14/9/2023 | 17/6/2026 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat Decision ManagerRedhat DroolsRedhat Jboss Middleware Text-only AdvisoriesRedhat Process Automation | 11/9/2023 | 17/6/2026 | A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server. | |
| Modificada | Crítica (9.8) | 0.74% | — | Ibos | 9/9/2023 | 17/6/2026 | A vulnerability was found in IBOS OA 4.5.5 and classified as critical. This issue affects some unknown processing of the file ?r=dashboard/database/optimize. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Crítica (9.8) | 0.74% | — | Ibos | 9/9/2023 | 17/6/2026 | A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 0.74% | — | Ibos | 9/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in IBOS OA 4.5.5. This affects an unknown part of the file ?r=dashboard/position/del. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated… | |
| Modificada | Crítica (9.8) | 0.74% | — | Ibos | 9/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in IBOS OA 4.5.5. Affected by this issue is some unknown functionality of the file ?r=file/dashboard/trash&op=del. The manipulation of the argument fids leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.80% | — | Ibos | 3/9/2023 | 17/6/2026 | A vulnerability was found in IBOS OA 4.5.5 and classified as critical. This issue affects some unknown processing of the file ?r=dashboard/user/export&uid=X. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated… | |
| Modificada | Alta (8.8) | 0.93% | 💥 PoC | Ibos | 3/9/2023 | 17/6/2026 | A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=diary/default/del of the component Delete Logs Handler. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (8.8) | 0.86% | — | Ibos | 3/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in IBOS OA 4.5.5. This affects an unknown part of the file ?r=email/api/delDraft&archiveId=0 of the component Delete Draft Handler. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.80% | — | Ibos | 1/9/2023 | 17/6/2026 | A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects the function addComment of the file ?r=weibo/comment/addcomment. The manipulation of the argument touid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this… | |
| Modificada | Crítica (9.8) | 0.84% | — | Ibos | 26/8/2023 | 17/6/2026 | A vulnerability was found in IBOS OA 4.5.5. It has been classified as critical. Affected is an unknown function of the file ?r=recruit/bgchecks/export&checkids=x. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 0.90% | — | Ibos | 25/8/2023 | 17/6/2026 | A vulnerability was found in IBOS OA 4.5.5. It has been declared as critical. This vulnerability affects unknown code of the file ?r=recruit/contact/export&contactids=x. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.4) | 0.33% | — | Webboss.io CMS | 3/8/2023 | 17/6/2026 | WebBoss.io CMS v3.7.0.1 contains a stored cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (5.4) | 0.33% | — | Webboss.io CMS | 3/8/2023 | 17/6/2026 | WebBoss.io CMS v3.7.0.1 contains a stored Cross-Site Scripting (XSS) vulnerability due to lack of input validation and output encoding. | |
| Modificada | Media (6.1) | 0.66% | — | Qibosoft | 3/8/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd and starttijd parameters of do/search.php. | |
| Modificada | Crítica (9.8) | 0.79% | — | Bbossgroups Bboss | 28/7/2023 | 17/6/2026 | bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument. | |
| Modificada | Crítica (9.8) | 0.68% | — | Ibos | 22/7/2023 | 17/6/2026 | A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /?r=recruit/resume/edit&op=status of the component Interview Handler. The manipulation of the argument resumeid leads to sql injection. The attack can be launched remotely.… | |
| Modificada | Alta (7.5) | 0.58% | — | Webboss.io CMS | 21/7/2023 | 17/6/2026 | An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET request. | |
| Modificada | Media (6.1) | 0.47% | — | Webboss.io CMS | 21/7/2023 | 17/6/2026 | WebBoss.io CMS before v3.7.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability. | |
| Modificada | Crítica (9.8) | 0.73% | — | Ibos | 21/7/2023 | 17/6/2026 | A vulnerability was found in IBOS OA 4.5.5. It has been declared as critical. Affected by this vulnerability is the function actionEdit of the file ?r=officialdoc/officialdoc/edit of the component Mobile Notification Handler. The manipulation leads to sql injection. The exploit has been disclosed to the public and may… |