Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

900 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.41%—Ribose RNP24/4/202317/6/2026
Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.
ModificadaMedia (5.3)0.90%—Ribose RNP24/4/202317/6/2026
Ribose RNP before 0.16.3 may hang when the input is malformed.
ModificadaAlta (7.5)0.49%—Ribose RNP21/4/202317/6/2026
Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm.
ModificadaCrítica (9.8)0.74%—Ibos15/4/202317/6/2026
A vulnerability, which was classified as critical, was found in IBOS 4.5.5. Affected is an unknown function of the file file/personal/del&op=recycle. The manipulation of the argument fids leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (6.5)0.57%—Jenkins Turboscript12/4/202317/6/2026
A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresponding to the attacker-specified repository.
ModificadaAlta (8.8)0.72%—Ibos31/3/202317/6/2026
A vulnerability has been found in IBOS up to 4.5.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the argument emailids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
ModificadaAlta (8.8)0.86%—Ibos30/3/202317/6/2026
A vulnerability classified as critical was found in IBOS 4.5.5. This vulnerability affects unknown code of the component htaccess Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this…
ModificadaAlta (8.8)0.72%—Ibos30/3/202317/6/2026
A vulnerability was found in IBOS 4.5.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?r=report/api/getlist of the component Report Search. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and…
ModificadaMedia (5.4)0.54%—Corebos21/3/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0.
ModificadaCrítica (9.8)0.74%—Ibos18/3/202317/6/2026
A vulnerability classified as critical has been found in IBOS 4.5.5. Affected is an unknown function of the file ApiController.php. The manipulation of the argument emailids leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (8.8)1.5%—Qibosoft Qibocms16/3/202317/6/2026
Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php
ModificadaMedia (6.1)0.51%—Ibos8/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in IBOS up to 4.5.5. Affected by this issue is some unknown functionality of the file mobil/index.php. The manipulation of the argument accesstoken leads to cross site scripting. The attack may be launched remotely. The identifier of this…
ModificadaAlta (7.5)1.4%—@nubosoftware/node-static Project @nubosoftware/node-staticNode-static Project Node-static6/3/202317/6/2026
All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
ModificadaAlta (7.5)0.60%—Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+623/2/202317/6/2026
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
ModificadaMedia (6.8)0.23%—Deyeinverter Inverter FirmwareRevolt-power Inverter FirmwareBosswerk Inverter Firmware13/2/202317/6/2026
A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation with the input 12345678 leads to use of hard-coded password. It is possible to…
ModificadaAlta (8.8)0.43%—Bosch B420 Firmware8/2/202317/6/2026
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publicly available B420 product using valid credentials, an insider attacker can gain…
ModificadaAlta (7.4)0.58%—Redhat Wildfly ElytronRedhat Jboss Enterprise Application Platform13/1/202317/6/2026
wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an…
ModificadaMedia (6.1)0.53%—Bostonsleep Slice17/12/202217/6/2026
A vulnerability, which was classified as problematic, was found in Boston Sleep slice up to 84.1.x. Affected is an unknown function of the component Layout Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 84.2.0 is able to address this issue.…
ModificadaCrítica (9.8)1.3%—Corebos13/12/202217/6/2026
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
ModificadaMedia (6.5)0.29%—Bosscms28/11/202217/6/2026
Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.
ModificadaCrítica (9.9)0.82%—Carel Boss Mini Firmware18/11/202217/6/2026
Carel Boss Mini 1.5.0 has Improper Access Control.
ModificadaCrítica (9.8)2.6%💥 PoCVmware Bosh EditorVmware Cloudfoundry Manifest YML SupportVmware Concourse CI Pipeline EditorVmware Spring Boot Tools+14/11/202217/6/2026
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the…
ModificadaMedia (4.8)0.33%—Bosch Videojet Multi 4000 Firmware27/10/202217/6/2026
Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET multi 4000 allows an attacker with administrative credentials to store JavaScript code which will be executed for all administrators accessing the same configuration option.
ModificadaMedia (4.7)0.34%—Bosch Videojet Multi 4000 Firmware27/10/202217/6/2026
An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.
ModificadaMedia (5.9)0.36%—Bosch Video Management SystemBosch Videojet Decoder 7513 Firmware30/9/202217/6/2026
Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or…