Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.8%—Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+1214/9/202317/6/2026
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
ModificadaMedia (5.3)0.65%—Jenkins Pipeline Maven Integration6/9/202317/6/2026
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.
ModificadaMedia (5.5)0.39%💥 PoCDisintegration Imaging5/9/202317/6/2026
disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
ModificadaMedia (6.1)0.34%—Wpo365 Mail Integration FOR Office 365 / Outlook23/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions.
ModificadaMedia (5.5)0.13%—Dell Replay Manager FOR VmwareDell Storage Integration Tools FOR VmwareDell Storage Vsphere Client Plugin16/8/202317/6/2026
Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to…
ModificadaMedia (6.1)0.36%—SAP Netweaver Process Integration8/8/202317/6/2026
In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, could result in Cross-Site Scripting (XSS) attack. On successful exploitation the attacker can cause limited impact on confidentiality and integrity of the system.
ModificadaMedia (6.5)0.82%—IBM B2B Advanced CommunicationsIBM Multi-enterprise Integration Gateway31/7/202317/6/2026
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976.
ModificadaMedia (5.4)0.35%—IBM B2B Advanced CommunicationsIBM Multi-enterprise Integration Gateway31/7/202317/6/2026
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
ModificadaMedia (4.3)0.38%—Exportfeed Woocommerce Etsy Integration12/7/202317/6/2026
The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.1. This is due to missing or incorrect nonce validation on the etcpf_delete_feed() function. This makes it possible for unauthenticated attackers to delete an export feed via a forged…
ModificadaMedia (6.5)0.57%—SAP Netweaver Process Integration11/7/202317/6/2026
The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow…
ModificadaMedia (6.5)0.57%—SAP Netweaver Process Integration11/7/202317/6/2026
The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not…
ModificadaAlta (8.8)0.26%—Icinga WEB Jira Integration5/7/202317/6/2026
icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no…
ModificadaAlta (7.1)0.36%—Bosch Building Integration System30/6/202317/6/2026
Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows local users to access data via network
ModificadaMedia (5.4)0.90%—Xwiki Ckeditor IntegrationXwiki30/6/202317/6/2026
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as removing technical documents, leading to loss of service and editing the…
ModificadaAlta (7.5)0.53%—Miniorange Active Directory Integration / Ldap Integration29/6/202317/6/2026
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to…
ModificadaMedia (4.8)0.44%—Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin19/6/202317/6/2026
The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaMedia (5.4)0.66%—Jenkins Sonargraph Integration14/6/202317/6/2026
Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (6.5)0.42%—Miniorange Active Directory Integration / Ldap Integration9/6/202317/6/2026
The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied…
ModificadaMedia (4.9)0.85%—Miniorange Active Directory Integration / Ldap Integration9/6/202317/6/2026
The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
ModificadaMedia (4.8)0.40%—Wp-matomo Integration Project Wp-matomo Integration28/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in André Bräkling WP-Matomo Integration (WP-Piwik) plugin <= 1.0.27 versions.
ModificadaAlta (8.8)0.26%—Crmperks Integration FOR Contact Form 7 AND Zoho Crm, Bigin26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions.
ModificadaAlta (7.5)0.57%—Jenkins Ns-nd Integration Performance Publisher16/5/202317/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.
ModificadaAlta (7.5)0.82%—Miniorange Active Directory Integration / Ldap Integration15/5/202317/6/2026
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
ModificadaMedia (5.3)0.70%—Next-engine Next Engine Integration10/5/202317/6/2026
Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.
ModificadaMedia (6.5)0.52%—Pingidentity PingfederatePingidentity Pingid Integration KITPingidentity Radius PCV25/4/202317/6/2026
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.