Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Wpthemespace Magical Addons FOR Elementor | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34. | |
| Analizada | Alta (7.8) | 0.40% | — | Ansys Spaceclaim | 3/5/2024 | 17/6/2026 | Ansys SpaceClaim X_B File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Aplazada | Media (4.3) | 0.20% | — | Bracketspace Simple Post NotesAI | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6. | |
| Aplazada | Media (5.9) | 0.36% | — | Bracketspace Advanced Cron ManagerAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BracketSpace Advanced Cron Manager – debug & control allows Stored XSS.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.2. | |
| Aplazada | Media (6.8) | 0.33% | 💥 PoC | Spacex Starlink Wifi Router GEN 2AI | 5/4/2024 | 17/6/2026 | SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page. | |
| Aplazada | Alta (8.8) | 0.54% | 💥 PoC | Spacex Starlink Wifi Router GEN 2AISpacex Starlink DishAI | 5/4/2024 | 17/6/2026 | SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reboot) via a DNS Rebinding attack. | |
| Aplazada | Media (6.5) | 0.35% | — | Interfacelab Media CloudAIAmazon S3AIImgixAIGoogle Cloud StorageAI+1 | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Interfacelab Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more allows Stored XSS.This issue affects Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and… | |
| Analizada | Media (4.3) | 0.58% | — | Monospace Directus | 12/3/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as an open redirect vulnerability as the user tries to log in via the API URL. There's a redirect that is done after successful login via the Auth API GET request to… | |
| Analizada | Baja (2.3) | 0.24% | — | Monospace Directus | 12/3/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various places (e.g., web server logs, browser history). Attackers gaining access to… | |
| Aplazada | Media (4.3) | 0.32% | — | Tibco Software Tibco Activespaces - Enterprise EditionAI | 12/3/2024 | 17/6/2026 | The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability that theoretically allows an Active Spaces client to passively observe data traffic to other clients. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition: versions… | |
| Analizada | Media (6.3) | 0.40% | — | Devolutions Workspace | 7/3/2024 | 17/6/2026 | Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions | |
| Analizada | Media (5.3) | 0.57% | — | Monospace Directus | 1/3/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped in compiled JS bundles which are accessible without authentication. With this information a malicious attacker can trivially look for known vulnerabilities in… | |
| Analizada | Alta (8.2) | 0.70% | — | Monospace Directus | 1/3/2024 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar email address as the victim with a one or more characters changed to use… | |
| Modificada | Baja (3.7) | 0.79% | — | KDE Plasma-workspace | 11/2/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp of the component Theme File Handler. The manipulation of the argument pluginId leads to path… | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Media (4.6) | 0.40% | — | Vmware Workspace ONE Launcher | 12/12/2023 | 17/6/2026 | Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information. | |
| Modificada | Media (6.5) | 0.59% | — | Devolutions Workspace | 7/12/2023 | 17/6/2026 | Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline. | |
| Modificada | Media (6.1) | 0.42% | — | Spaceapplications Yacms | 20/11/2023 | 17/6/2026 | An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking. | |
| Modificada | Media (5.4) | 0.60% | — | Spaceapplications Yacms | 20/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the text variable scriptContainer of the ScriptViewer. | |
| Modificada | Media (5.4) | 0.60% | — | Spaceapplications Yacms | 20/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via crafted telecommand in the timeline view of the ArchiveBrowser. | |
| Modificada | Media (6.1) | 0.40% | — | Vmware Workspace ONE UEM | 31/10/2023 | 17/6/2026 | VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user. | |
| Modificada | Media (4.8) | 0.48% | — | Deanoakley Photospace Responsive Gallery | 20/10/2023 | 17/6/2026 | The Photospace Responsive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘psres_button_size’ parameter in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Media (5.4) | 0.53% | — | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript. | |
| Modificada | Media (5.4) | 0.43% | — | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the bucket. The user can then open the uploaded display by selecting Telemetry from the menu and… | |
| Modificada | Media (6.5) | 0.69% | — | Monospace Directus | 19/10/2023 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. A malicious user could leverage this bug to crash Directus. This issue has been addressed in… |