Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.41% | — | Ribose RNP | 24/4/2023 | 17/6/2026 | Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use. | |
| Modificada | Media (5.3) | 0.90% | — | Ribose RNP | 24/4/2023 | 17/6/2026 | Ribose RNP before 0.16.3 may hang when the input is malformed. | |
| Modificada | Alta (7.5) | 0.49% | — | Ribose RNP | 21/4/2023 | 17/6/2026 | Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm. | |
| Modificada | Crítica (9.8) | 0.74% | — | Ibos | 15/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in IBOS 4.5.5. Affected is an unknown function of the file file/personal/del&op=recycle. The manipulation of the argument fids leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (6.5) | 0.57% | — | Jenkins Turboscript | 12/4/2023 | 17/6/2026 | A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresponding to the attacker-specified repository. | |
| Modificada | Alta (8.8) | 0.72% | — | Ibos | 31/3/2023 | 17/6/2026 | A vulnerability has been found in IBOS up to 4.5.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the argument emailids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 0.86% | — | Ibos | 30/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in IBOS 4.5.5. This vulnerability affects unknown code of the component htaccess Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this… | |
| Modificada | Alta (8.8) | 0.72% | — | Ibos | 30/3/2023 | 17/6/2026 | A vulnerability was found in IBOS 4.5.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?r=report/api/getlist of the component Report Search. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.4) | 0.54% | — | Corebos | 21/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0. | |
| Modificada | Crítica (9.8) | 0.74% | — | Ibos | 18/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in IBOS 4.5.5. Affected is an unknown function of the file ApiController.php. The manipulation of the argument emailids leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (8.8) | 1.5% | — | Qibosoft Qibocms | 16/3/2023 | 17/6/2026 | Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php | |
| Modificada | Media (6.1) | 0.51% | — | Ibos | 8/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in IBOS up to 4.5.5. Affected by this issue is some unknown functionality of the file mobil/index.php. The manipulation of the argument accesstoken leads to cross site scripting. The attack may be launched remotely. The identifier of this… | |
| Modificada | Alta (7.5) | 1.4% | — | @nubosoftware/node-static Project @nubosoftware/node-staticNode-static Project Node-static | 6/3/2023 | 17/6/2026 | All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function. | |
| Modificada | Alta (7.5) | 0.60% | — | Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+6 | 23/2/2023 | 17/6/2026 | The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol. | |
| Modificada | Media (6.8) | 0.23% | — | Deyeinverter Inverter FirmwareRevolt-power Inverter FirmwareBosswerk Inverter Firmware | 13/2/2023 | 17/6/2026 | A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation with the input 12345678 leads to use of hard-coded password. It is possible to… | |
| Modificada | Alta (8.8) | 0.43% | — | Bosch B420 Firmware | 8/2/2023 | 17/6/2026 | An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publicly available B420 product using valid credentials, an insider attacker can gain… | |
| Modificada | Alta (7.4) | 0.58% | — | Redhat Wildfly ElytronRedhat Jboss Enterprise Application Platform | 13/1/2023 | 17/6/2026 | wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an… | |
| Modificada | Media (6.1) | 0.53% | — | Bostonsleep Slice | 17/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Boston Sleep slice up to 84.1.x. Affected is an unknown function of the component Layout Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 84.2.0 is able to address this issue.… | |
| Modificada | Crítica (9.8) | 1.3% | — | Corebos | 13/12/2022 | 17/6/2026 | PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. | |
| Modificada | Media (6.5) | 0.29% | — | Bosscms | 28/11/2022 | 17/6/2026 | Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module. | |
| Modificada | Crítica (9.9) | 0.82% | — | Carel Boss Mini Firmware | 18/11/2022 | 17/6/2026 | Carel Boss Mini 1.5.0 has Improper Access Control. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 PoC | Vmware Bosh EditorVmware Cloudfoundry Manifest YML SupportVmware Concourse CI Pipeline EditorVmware Spring Boot Tools+1 | 4/11/2022 | 17/6/2026 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the… | |
| Modificada | Media (4.8) | 0.33% | — | Bosch Videojet Multi 4000 Firmware | 27/10/2022 | 17/6/2026 | Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET multi 4000 allows an attacker with administrative credentials to store JavaScript code which will be executed for all administrators accessing the same configuration option. | |
| Modificada | Media (4.7) | 0.34% | — | Bosch Videojet Multi 4000 Firmware | 27/10/2022 | 17/6/2026 | An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user. | |
| Modificada | Media (5.9) | 0.36% | — | Bosch Video Management SystemBosch Videojet Decoder 7513 Firmware | 30/9/2022 | 17/6/2026 | Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or… |