Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.92% | — | Vmware Workspace ONE Content | 28/2/2023 | 17/6/2026 | VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode. | |
| Modificada | Alta (7.8) | 0.22% | — | Citrix Workspace | 16/2/2023 | 17/6/2026 | Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | |
| Modificada | Media (5.5) | 0.26% | — | Citrix Workspace | 16/2/2023 | 17/6/2026 | A malicious user can cause log files to be written to a directory that they do not have permission to write to. | |
| Modificada | Media (5.4) | 0.58% | — | Onlyoffice Workspace | 7/2/2023 | 17/6/2026 | Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition. | |
| Modificada | Crítica (9.8) | 0.96% | — | Monospace Directus | 26/12/2022 | 17/6/2026 | In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true. | |
| Modificada | Media (5.4) | 0.67% | — | Photospace Gallery Project Photospace Gallery | 29/11/2022 | 17/6/2026 | The Photospace Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters saved via the update() function in versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.55% | 💥 PoC | Caehealthcare Learningspace Enterprise | 23/11/2022 | 17/6/2026 | CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup. | |
| Modificada | Media (4.8) | 0.50% | — | Clevelandwebdeveloper Spacer | 21/11/2022 | 17/6/2026 | The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Crítica (9.8) | 0.88% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. | |
| Modificada | Media (6.1) | 0.46% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window. | |
| Modificada | Crítica (9.8) | 0.88% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 0.99% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 1.0% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Media (4.8) | 0.50% | — | Spacexchimp Social Media Follow Buttons BAR | 30/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress. | |
| Modificada | Alta (7.8) | 0.58% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_T files. The… | |
| Modificada | Alta (7.8) | 0.58% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.58% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.81% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.88% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.58% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.58% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… |