Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1019 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.56% | — | Hidglobal Safe | 7/6/2023 | 17/6/2026 | The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an internal user and then manipulate the… | |
| Modificada | Alta (8.8) | 1.1% | — | Marvalglobal MSM | 7/6/2023 | 17/6/2026 | Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server. | |
| Modificada | Media (5.5) | 0.11% | — | Marvalglobal MSM | 7/6/2023 | 17/6/2026 | Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key. | |
| Modificada | Crítica (9.8) | 0.99% | — | Marvalglobal MSM | 7/6/2023 | 17/6/2026 | Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application. | |
| Modificada | Alta (7.5) | 0.62% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (4.3) | 1.2% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which… | |
| Modificada | Media (6.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.3) | 0.56% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 3/5/2023 | 17/6/2026 | When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.5) | 0.19% | — | HP OneviewHPE Oneview Global Dashboard | 25/4/2023 | 17/6/2026 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | |
| Modificada | Alta (7.2) | 0.97% | — | Meinbergglobal Lantime Firmware | 24/4/2023 | 17/6/2026 | In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands. | |
| Modificada | Media (5.5) | 0.18% | — | HPE Oneview Global Dashboard | 14/4/2023 | 17/6/2026 | An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials | |
| Modificada | Media (6.3) | 0.11% | — | Paloaltonetworks Globalprotect | 12/4/2023 | 17/6/2026 | A local file deletion vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a user to delete system files from the endpoint with elevated privileges through a race condition. | |
| Modificada | Crítica (9.8) | 1.5% | — | Sato-global Cl4nx Plus Firmware | 31/3/2023 | 17/6/2026 | An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unauthenticated attackers with access to execute commands intended only for valid/authenticated users, such as file uploads and configuration changes. | |
| Modificada | Crítica (9.8) | 49% | 💥 Exploit | Dcnglobal Dcbi-netlog-lab Firmware | 26/3/2023 | 17/6/2026 | An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request. | |
| Modificada | Crítica (9.1) | 0.82% | — | Keystorage Global Facilities Management Software | 10/2/2023 | 17/6/2026 | Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes. | |
| Modificada | Alta (7.5) | 1.0% | — | Rubyonrails Globalid | 9/2/2023 | 17/6/2026 | A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately. | |
| Modificada | Alta (7.3) | 0.21% | — | Oracle Global Lifecycle Management Nextgen OUI Framework | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where… | |
| Modificada | Crítica (9.8) | 1.5% | — | Global-modules-path Project Global-modules-path | 13/1/2023 | 17/6/2026 | Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function. | |
| Modificada | Crítica (9.8) | 0.81% | — | Globalpom-utils Project Globalpom-utils | 6/1/2023 | 17/6/2026 | A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/FileResourceManagerProvider.java. The manipulation leads to… | |
| Modificada | Media (6.1) | 0.38% | — | HPE Oneview Global Dashboard | 12/12/2022 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD). | |
| Modificada | Alta (8.7) | 77% | 💥 Exploit | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+7 | 7/12/2022 | 17/6/2026 | In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which… | |
| Modificada | Alta (8.8) | 92% | 💥 Exploit | F5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Access Policy Manager+8 | 7/12/2022 | 17/6/2026 | In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.5) | 0.89% | — | Syncee - Global Dropshipping | 5/12/2022 | 17/6/2026 | The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator's account. | |
| Modificada | Alta (7.8) | 0.42% | — | Nttdata Terasoluna Global FrameworkNttdata Terasoluna Server Framework FOR Java (rich) | 5/12/2022 | 17/6/2026 | TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The vulnerability is caused by an improper input… | |
| Modificada | Baja (3.7) | 0.27% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 19/10/2022 | 17/6/2026 | On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile… |