Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.58% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.58% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.54% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The… | |
| Modificada | Alta (7.8) | 0.48% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The… | |
| Modificada | Media (4.3) | 0.65% | — | Photospace Gallery Project Photospace Gallery | 12/9/2022 | 17/6/2026 | Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with subscriber or higher role to change plugin settings. | |
| Modificada | Baja (3.3) | 0.20% | — | IBM Planning Analytics Workspace | 8/9/2022 | 17/6/2026 | IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 217371. | |
| Modificada | Media (6.5) | 0.95% | — | Monospace Directus | 19/8/2022 | 17/6/2026 | Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` endpoint. This vulnerability has been patched and release v9.15.0 contains the… | |
| Modificada | Alta (7.2) | 1.4% | 💥 PoC | Duraspace Dspace | 1/8/2022 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path traversal vulnerability. This means a malicious SAF (simple archive format) package could cause a file/directory to be created anywhere the… | |
| Modificada | Alta (7.2) | 1.1% | 💥 PoC | Duraspace Dspace | 1/8/2022 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI resumable upload implementations in SubmissionController and FileUploadRequest are vulnerable to multiple path traversal attacks, allowing an attacker to… | |
| Modificada | Media (6.1) | 0.73% | — | Duraspace Dspace | 1/8/2022 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI controlled vocabulary servlet is vulnerable to an open redirect attack, where an attacker can craft a malicious URL that looks like a legitimate… | |
| Modificada | Media (6.1) | 0.77% | 💥 PoC | Duraspace Dspace | 1/8/2022 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI "Request a Copy" feature does not properly escape values submitted and stored from the "Request a Copy" form. This means that item requests could be… | |
| Modificada | Media (6.1) | 0.78% | — | Duraspace Dspace | 1/8/2022 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI spellcheck "Did you mean" HTML escapes the data-spell attribute in the link, but not the actual displayed text. Similarly, the JSPUI autocomplete HTML does… | |
| Modificada | Media (5.3) | 0.70% | — | Duraspace Dspace | 1/8/2022 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. When an "Internal System Error" occurs in the JSPUI, then entire exception (including stack trace) is available. Information in this stacktrace may be useful to an… | |
| Modificada | Media (5.3) | 0.90% | — | Duraspace Dspace | 1/8/2022 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL of the withdrawn Item. This… | |
| Modificada | Alta (7.5) | 17% | — | Checkpoint Capsule Workspace | 18/7/2022 | 17/6/2026 | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could result in application crashing but could not be used to gather any sensitive information. | |
| Modificada | Media (6.5) | 2.1% | 💥 Exploit | Montala Resourcespace | 17/7/2022 | 17/6/2026 | In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value. | |
| Modificada | Media (4.8) | 0.59% | — | Bracketspace Simple Post Notes | 17/7/2022 | 17/6/2026 | The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.8) | 70% | 💥 Exploit | Schneider-electric Spacelogic C-bus Home Controller Firmware | 13/7/2022 | 17/6/2026 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460… | |
| Modificada | Media (6.1) | 0.57% | — | Siemens Teamcenter Active Workspace | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in Teamcenter Active Workspace V5.2 (All versions < V5.2.9), Teamcenter Active Workspace V6.0 (All versions < V6.0.3). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected application that could allow an attacker to execute malicious code… | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (7.8) | 2.4% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Vrealize Suite Lifecycle Manager | 20/5/2022 | 17/6/2026 | VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. |