Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.74% | — | Ibos | 20/7/2023 | 17/6/2026 | A vulnerability was found in IBOS OA 4.5.5 and classified as critical. This issue affects some unknown processing of the file ?r=article/category/del of the component Delete Category Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.62% | — | Ibos | 20/7/2023 | 17/6/2026 | A vulnerability was found in IBOS OA 4.5.5 and classified as critical. Affected by this issue is the function actionExport of the file ?r=contact/default/export of the component Personal Office Address Book. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Carel Boss Mini Firmware | 12/7/2023 | 17/6/2026 | A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (8.8) | 0.75% | — | Ibos | 11/7/2023 | 17/6/2026 | A vulnerability was found in IBOS OA 4.5.5. It has been classified as critical. Affected is the function createDeleteCommand of the file ?r=article/default/delete of the component Delete Packet. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (7.1) | 0.36% | — | Bosch Building Integration System | 30/6/2023 | 17/6/2026 | Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows local users to access data via network | |
| Modificada | Alta (7.2) | 0.76% | — | Ibos | 30/6/2023 | 17/6/2026 | A vulnerability classified as critical was found in IBOS OA 4.5.5. Affected by this vulnerability is the function actionEdit of the file ?r=dashboard/roleadmin/edit&op=member of the component Add User Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit… | |
| Modificada | Alta (7.2) | 0.88% | — | Ibos | 28/6/2023 | 17/6/2026 | A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects the function actionExport of the file ?r=recruit/interview/export&interviews=x of the component Interview Management Export. The manipulation of the argument interviews leads to sql injection. The exploit has been… | |
| Modificada | Media (6.5) | 0.60% | — | Bosch Cpp13 FirmwareBosch Cpp14 Firmware | 15/6/2023 | 17/6/2026 | Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256. | |
| Modificada | Alta (7.7) | 0.46% | — | Bosch Video Management SystemBosch Video Management System ViewerBosch Divar IP 3000 FirmwareBosch Divar IP 6000 Firmware+5 | 15/6/2023 | 17/6/2026 | Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request. | |
| Modificada | Media (4.4) | 0.56% | — | Fibosearch | 9/6/2023 | 17/6/2026 | The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Crítica (9.8) | 0.74% | — | Ibos | 5/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in IBOS 4.5.5. Affected by this issue is the function actionDel of the file ?r=dashboard/approval/del. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-230690 is the identifier… | |
| Modificada | Media (5.4) | 0.47% | — | Corebos | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc. | |
| Modificada | Media (6.5) | 0.32% | — | Corebos | 2/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Media (5.4) | 0.51% | — | Corebos | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Media (5.4) | 0.52% | — | Tsolucio Corebos | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Media (5.4) | 0.57% | — | Corebos | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Crítica (9.8) | 0.60% | — | Corebos | 2/6/2023 | 17/6/2026 | Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Media (5.3) | 0.54% | — | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using. Users should upgrade to version 3.3.5, which… | |
| Modificada | Media (6.5) | 0.62% | — | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the `/display/map` API route inside the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values in to the… | |
| Modificada | Media (6.5) | 0.62% | — | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.5 in the `nameFilter` function used throughout the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values for… | |
| Modificada | Media (6.5) | 0.63% | — | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `/dataset/data/{id}` API route inside the CMS starting in version 1.4.0 and prior to versions 2.3.17 and 3.3.5. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted… | |
| Modificada | Alta (8.8) | 7.0% | 💥 Exploit | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded to the CMS via the layout import function by an authenticated user which would allow creation of files outside of the CMS library directory as the webserver user. This… | |
| Modificada | Media (6.5) | 0.43% | — | Redhat Build OF QuarkusRedhat Jboss A-mqRedhat KeycloakRedhat Migration Toolkit FOR Runtimes+1 | 26/5/2023 | 17/6/2026 | A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the… | |
| Modificada | Crítica (9.8) | 0.62% | — | Cityboss E-municipality | 24/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection. This issue affects E-municipality: before 6.05. | |
| Modificada | Alta (8.8) | 0.27% | — | Robosoft Robogallery | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.11 versions. |