Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.92%—Vmware Workspace ONE Content28/2/202317/6/2026
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass the VMware Workspace ONE Content passcode.
ModificadaAlta (7.8)0.22%—Citrix Workspace16/2/202317/6/2026
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
ModificadaMedia (5.5)0.26%—Citrix Workspace16/2/202317/6/2026
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
ModificadaMedia (5.4)0.58%—Onlyoffice Workspace7/2/202317/6/2026
Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition.
ModificadaCrítica (9.8)0.96%—Monospace Directus26/12/202217/6/2026
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
ModificadaMedia (5.4)0.67%—Photospace Gallery Project Photospace Gallery29/11/202217/6/2026
The Photospace Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters saved via the update() function in versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.4)0.55%💥 PoCCaehealthcare Learningspace Enterprise23/11/202217/6/2026
CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.
ModificadaMedia (4.8)0.50%—Clevelandwebdeveloper Spacer21/11/202217/6/2026
The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
ModificadaCrítica (9.8)0.88%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
ModificadaMedia (6.1)0.46%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
ModificadaCrítica (9.8)0.88%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaCrítica (9.8)0.99%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaCrítica (9.8)1.0%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaMedia (4.8)0.50%—Spacexchimp Social Media Follow Buttons BAR30/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73 at WordPress.
ModificadaAlta (7.8)0.58%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_T files. The…
ModificadaAlta (7.8)0.58%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.58%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.81%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.62%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.62%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.88%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.58%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.62%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.62%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
ModificadaAlta (7.8)0.58%—Ansys Spaceclaim15/9/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The…
Orbitaley — Vulnerabilidades