Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.60% | — | Supremainc Biostar 2 | 3/8/2023 | 17/6/2026 | A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitrary SQL commands. | |
| Modificada | Alta (7.5) | 0.73% | — | Supremainc Biostar 2 | 3/8/2023 | 17/6/2026 | A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the server's web server. | |
| Modificada | Alta (8.8) | 1.6% | — | Supremainc Biostar 2 | 3/8/2023 | 17/6/2026 | An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server. | |
| Modificada | Alta (7.5) | 0.56% | — | Supremainc Biostar 2 | 3/8/2023 | 17/6/2026 | An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers. | |
| Modificada | Media (6.1) | 0.41% | — | Fivestarplugins Five Star Restaurant Menu | 25/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Fivestarplugins Five Star Restaurant Menu | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions. | |
| Modificada | Media (6.1) | 0.60% | — | Instareza Mail Control | 12/7/2023 | 17/6/2026 | The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Crítica (9.8) | 0.56% | — | Johnsoncontrols Istar Ultra FirmwareJohnsoncontrols Istar Ultra LT FirmwareJohnsoncontrols Istar Ultra G2 FirmwareJohnsoncontrols Edge G2 Firmware | 11/7/2023 | 17/6/2026 | An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights. | |
| Modificada | Alta (8.1) | 4.4% | 💥 Exploit | Starface | 15/6/2023 | 17/6/2026 | RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application's database generally has become best practice to protect… | |
| Modificada | Media (6.1) | 0.38% | — | Zestard Admin Side Data Storage FOR Contact Form 7 | 15/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions. | |
| Modificada | Alta (7.2) | 22% | 💥 PoC | Mitrastar Gpt-2741gnac Firmware | 6/6/2023 | 9/7/2026 | A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authenticated user to execute arbitrary OS commands by sending specially crafted input to the router via the ping function. | |
| Modificada | Alta (7.5) | 2.0% | — | Encode Starlette | 1/6/2023 | 17/6/2026 | Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette. | |
| Modificada | Alta (8.8) | 0.26% | — | Brainstormforce Starter Templates | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions. | |
| Modificada | Alta (8.8) | 0.86% | — | Supremainc Biostar 2 | 22/5/2023 | 17/6/2026 | Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation, which can be exploited to gain full… | |
| Modificada | Baja (3.3) | 0.49% | — | Microsoft Azure ARC Jumpstart | 18/5/2023 | 17/6/2026 | Azure Arc Jumpstart Information Disclosure Vulnerability | |
| Modificada | Alta (7.1) | 0.49% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. | |
| Modificada | Alta (7.1) | 0.49% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (6.5) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discovered that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is… | |
| Modificada | Media (6.1) | 0.49% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… |