Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.41% | — | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file. | |
| Modificada | Crítica (9.1) | 1.6% | — | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request. | |
| Modificada | Alta (7.5) | 1.0% | 💥 PoC | Spaceapplications Yamcs | 19/10/2023 | 17/6/2026 | Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 35% | — | Schneider-electric Spacelogic C-bus Toolkit | 4/10/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command. | |
| Modificada | Alta (8.8) | 0.62% | — | Bydemes Airspace Cctv WEB Service | 3/10/2023 | 17/6/2026 | The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access. | |
| Modificada | Alta (8.6) | 0.84% | — | Spice-space Spice-server | 22/8/2023 | 17/6/2026 | An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects. | |
| Modificada | Media (6.5) | 0.50% | — | Monospace Directus | 25/7/2023 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permission filters (i.e. `user_created IS $CURRENT_USER`) are not properly checked when using GraphQL subscription resulting in unauthorized users getting event on their… | |
| Modificada | Media (4.7) | 0.13% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space ManagementIBM Spectrum Protect FOR Virtual Environments | 19/7/2023 | 17/6/2026 | IBM Spectrum Protect 8.1.0.0 through 8.1.17.0 could allow a local user to cause a denial of service due to due to improper time-of-check to time-of-use functionality. IBM X-Force ID: 256012. | |
| Modificada | Alta (7.6) | 0.55% | — | Oracle Hyperion Workspace | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Hyperion Workspace product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks… | |
| Modificada | Media (6.5) | 1.2% | — | Jenkins Mathworks Polyspace | 12/7/2023 | 17/6/2026 | Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jenkins controller file systems. | |
| Modificada | Media (5.5) | 0.18% | — | Citrix Workspace | 10/7/2023 | 17/6/2026 | A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. | |
| Modificada | Media (5.4) | 0.37% | — | Palantir Foundry Workspace-server | 29/6/2023 | 17/6/2026 | A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with… | |
| Modificada | Alta (7.8) | 0.34% | — | Dualspace Lock Master | 30/5/2023 | 17/6/2026 | The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of… | |
| Modificada | Media (6.1) | 0.35% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector | 30/5/2023 | 17/6/2026 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | |
| Modificada | Alta (7.8) | 0.18% | — | Devolutions Workspace | 24/4/2023 | 17/6/2026 | Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This… | |
| Modificada | Alta (7.1) | 0.74% | — | Dualspace Lock Master | 14/4/2023 | 17/6/2026 | An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludashi.superlock.util.pref.SharedPrefProviderEntryMethod: insert of the android.net.Uri.insert method. | |
| Modificada | Alta (7.8) | 0.38% | — | Dualspace Space Clean & Super Cleaner | 14/4/2023 | 17/6/2026 | An issue found in DUALSPACE v.1.1.3 allows a local attacker to gain privileges via the key_ad_new_user_avoid_time field. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dualspace Super Security | 11/4/2023 | 17/6/2026 | An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url, KEY_Cirus_scan_whitelist and KEY_AD_NEW_USER_AVOID_TIME parameters. | |
| Modificada | Alta (7.5) | 1.1% | — | Dualspace Super Security | 11/4/2023 | 17/6/2026 | An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files. | |
| Modificada | Media (6.5) | 1.1% | — | Monospace Directus | 4/4/2023 | 17/6/2026 | An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests. | |
| Modificada | Crítica (9.8) | 0.46% | — | Componentspace Saml | 24/3/2023 | 9/7/2026 | ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust… | |
| Modificada | Media (5.5) | 0.31% | — | Monospace Directus | 24/3/2023 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version 9.23.3. | |
| Modificada | Media (4.3) | 0.60% | — | Monospace Directus | 7/3/2023 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. In versions prior to 9.16.0 users with read access to the `password` field in `directus_users` can extract the argon2 password hashes by brute forcing the export functionality combined with a `_starts_with` filter. This allows the user to… | |
| Modificada | Alta (7.5) | 0.96% | — | Monospace Directus | 3/3/2023 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side Request Forgery (SSRF) when importing a file from a remote web server (POST to `/files/import`). An attacker can bypass the security controls by performing a DNS rebinding attack and view sensitive… |