Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.18% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.15% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.30% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.23% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges. | |
| Modificada | Media (4.7) | 0.11% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition. | |
| Modificada | Alta (7.8) | 0.22% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges. | |
| Modificada | Alta (7.8) | 0.13% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges. | |
| Modificada | Media (5.5) | 0.14% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context. | |
| Modificada | Alta (8.3) | 0.87% | — | Oracle Mysql Connector/jNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.5) | 1.6% | — | Apache Tomcat Connectors | 13/9/2023 | 17/6/2026 | Important: Authentication Bypass CVE-2023-41081 The mod_jk component of Apache Tomcat Connectors in some circumstances, such as when a configuration included "JkOptions +ForwardDirectories" but the configuration did not provide explicit mounts for all possible proxied requests, mod_jk would use an implicit mapping and… | |
| Modificada | Media (4.3) | 0.38% | — | Qualys Container Scanning Connector | 8/9/2023 | 17/6/2026 | An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified… | |
| Modificada | Alta (7.8) | 0.20% | — | Forescout Secureconnector | 3/9/2023 | 17/6/2026 | ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element | |
| Modificada | Media (4.8) | 0.37% | — | Never5 Post Connector | 8/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Never5 Post Connector plugin <= 1.0.9 versions. | |
| Modificada | Media (6.5) | 0.58% | — | Jenkins Qualys WEB APP Scanning Connector | 26/7/2023 | 17/6/2026 | Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.39% | — | Gsheetconnector Caldera Forms Google Sheets Connector | 17/7/2023 | 17/6/2026 | The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Alta (8.8) | 0.39% | — | Gsheetconnector Woocommerce Google Sheet Connector | 17/7/2023 | 17/6/2026 | The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Analizada | Crítica (9.8) | 1.3% | — | Apache Eventmesh-connector-rabbitmq | 17/7/2023 | 17/6/2026 | CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can use the code under the master branch in project… | |
| Modificada | Media (6.1) | 0.72% | — | Gsheetconnector Ninja Forms Google Sheet Connector | 4/7/2023 | 17/6/2026 | The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.46% | — | Gsheetconnector Elementor Forms Google Sheet Connector | 4/7/2023 | 17/6/2026 | The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as… | |
| Modificada | Media (6.1) | 0.46% | — | Gsheetconnector Wpforms Google Sheet Connector | 4/7/2023 | 17/6/2026 | The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.46% | — | Gsheetconnector CF7 Google Sheets Connector | 4/7/2023 | 17/6/2026 | The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.5) | 0.31% | — | Gsheetconnector Gravity Forms Google Sheets Connector | 27/6/2023 | 17/6/2026 | The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Media (6.1) | 0.55% | — | Zscaler Client Connector | 22/6/2023 | 17/6/2026 | When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login. | |
| Modificada | Media (6.1) | 0.45% | — | Zscaler Client Connector | 22/6/2023 | 17/6/2026 | A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain. |