Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.46% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 17/7/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380. | |
| Modificada | Media (4.3) | 0.38% | — | Coolplugins Process Steps Template Designer | 12/7/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request… | |
| Modificada | Media (6.5) | 0.57% | — | SAP Netweaver Process Integration | 11/7/2023 | 17/6/2026 | The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow… | |
| Modificada | Media (6.5) | 0.57% | — | SAP Netweaver Process Integration | 11/7/2023 | 17/6/2026 | The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not… | |
| Modificada | Media (5.5) | 0.17% | — | IBM Robotic Process Automation | 27/6/2023 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insufficient security configuration which may allow creation of namespaces within a cluster. IBM X-Force ID: 244500. | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Robotic Process Automation | 27/6/2023 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redis container which may provide elevated privileges. IBM X-Force ID: 244074. | |
| Modificada | Media (5.5) | 0.77% | — | Microsoft SysinternalsMicrosoft Sysinternals Process Monitor | 14/6/2023 | 17/6/2026 | Sysinternals Process Monitor for Windows Denial of Service Vulnerability | |
| Modificada | Alta (8.8) | 0.56% | — | Coolplugins Process Steps Template Designer | 7/6/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such… | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+178 | 6/6/2023 | 17/6/2026 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Apq8076 FirmwareQualcomm Apq8092 Firmware+279 | 6/6/2023 | 17/6/2026 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | |
| Modificada | Alta (7.5) | 0.35% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+238 | 6/6/2023 | 17/6/2026 | Transient DOS due to improper authorization in Modem | |
| Modificada | Alta (7.8) | 1.3% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+238 | 6/6/2023 | 17/6/2026 | Memory corruption due to double free in Core while mapping HLOS address to the list. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+238 | 6/6/2023 | 17/6/2026 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | |
| Modificada | Media (5.5) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+344 | 6/6/2023 | 17/6/2026 | information disclosure due to cryptographic issue in Core during RPMB read request. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm Wcn3998 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 FirmwareQualcomm Wcn685x-1 Firmware+161 | 2/5/2023 | 17/6/2026 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8052 Firmware+216 | 2/5/2023 | 17/6/2026 | Memory corruption in Graphics while importing a file. | |
| Modificada | Alta (7.5) | 0.60% | — | IBM Infosphere Information ServerIBM JavaIBM Websphere Application ServerIBM Z/transaction Processing Facility | 29/4/2023 | 17/6/2026 | IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188. | |
| Modificada | Media (6.5) | 0.59% | — | Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon Momentum Unity M1E Processor FirmwareSchneider-electric Modicon Mc80 Firmware+4 | 19/4/2023 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user. | |
| Modificada | Alta (7.5) | 0.62% | — | Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon Momentum Unity M1E Processor FirmwareSchneider-electric Modicon Mc80 Firmware+3 | 19/4/2023 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+349 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | |
| Modificada | Alta (7.5) | 0.41% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+181 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+221 | 13/4/2023 | 17/6/2026 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | |
| Modificada | Media (6.8) | 0.19% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+222 | 13/4/2023 | 17/6/2026 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | |
| Modificada | Alta (7.8) | 0.08% | — | Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+215 | 13/4/2023 | 17/6/2026 | Memory corruption due to double free in core while initializing the encryption key. |