Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.86% | — | Cisco Staros | 9/5/2023 | 17/6/2026 | A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Alta (8.8) | 1.3% | — | Mitrastar Gpt-2741gnac-n2 Firmware | 5/5/2023 | 17/6/2026 | MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the ping function. | |
| Modificada | Alta (7.8) | 0.43% | — | Serenity SereneSerenity Startsharp | 27/4/2023 | 17/6/2026 | An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be used a second time to change the password of the corresponding user. The token… | |
| Modificada | Media (5.3) | 1.0% | — | Serenity SereneSerenity Startsharp | 27/4/2023 | 17/6/2026 | An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist. | |
| Modificada | Media (6.1) | 0.78% | — | Serenity SereneSerenity Startsharp | 27/4/2023 | 17/6/2026 | An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to upload .html or .htm files containing an XSS payload. The resulting link can be sent to an administrator user. | |
| Modificada | Alta (7.5) | 1.3% | — | Encode Starlette | 21/4/2023 | 15/7/2026 | There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service. | |
| Modificada | Media (5.3) | 0.47% | — | Stargate-bukkit Project Stargate-bukkit | 19/4/2023 | 17/6/2026 | Stargate-Bukkit is a mod for the minecraft video game which adds a portal focused environment. In affected versions Minecarts with chests will drop their items when teleporting through a portal; when they reappear, they will still have their items impacting the integrity of the game world. The teleport code has since… | |
| Modificada | Media (6.5) | 7.6% | 💥 Exploit | Supremainc Biostar 2 | 29/3/2023 | 9/7/2026 | Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1. | |
| Modificada | Alta (8.8) | 0.27% | — | Universal Star Rating Project Universal Star Rating | 17/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chasil Universal Star Rating plugin <= 2.1.0 version. | |
| Modificada | Media (6.1) | 0.38% | — | Yasr - YET Another Stars Rating Project Yasr - YET Another Stars Rating | 16/3/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions. | |
| Modificada | Alta (7.5) | 0.60% | — | Saysis Starcities | 10/3/2023 | 17/6/2026 | Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows Collect Data from Common Resource Locations. This issue affects Starcities: through 1.3. | |
| Modificada | Crítica (9.8) | 0.66% | — | Saysis Starcities | 10/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3. | |
| Modificada | Media (6.1) | 0.38% | — | Saysis Starcities | 6/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saysis Computer Starcities allows Cross-Site Scripting (XSS). This issue affects Starcities: before 1.1. | |
| Modificada | Alta (7.8) | 0.42% | 💥 PoC | Starsoftcomm Coocare | 3/3/2023 | 17/6/2026 | starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload. | |
| Modificada | Alta (7.5) | 1.0% | — | Starliteproject Starlite | 15/2/2023 | 17/6/2026 | Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing in `starlite` allows a potentially unauthenticated attacker to consume a large amount of CPU time and RAM. The multipart body parser processes an unlimited number of file parts and an unlimited… | |
| Modificada | Alta (7.3) | 1.5% | 💥 PoC | Rockstargames Grand Theft Auto V | 22/1/2023 | 17/6/2026 | Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023. | |
| Modificada | Alta (7.5) | 0.54% | — | Yeastar N824 FirmwareYeastar N412 Firmware | 20/1/2023 | 17/6/2026 | In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and download it, revealing admin hash, allowing, once cracked, to login inside the Configuration Panel, otherwise, replacing the hash in the archive and restoring it on the device which will change admin… | |
| Modificada | Media (4.8) | 0.53% | — | 404 TO Start Project 404 TO Start | 9/1/2023 | 17/6/2026 | The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (8.8) | 0.92% | — | Kadencewp Starter Templates | 9/1/2023 | 17/6/2026 | The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Crítica (9.8) | 1.1% | — | Starcounter-jack Json-patch | 25/12/2022 | 17/6/2026 | A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has… | |
| Modificada | Media (6.1) | 0.53% | — | Starter-public-edition-4 Project Starter-public-edition-4 | 17/12/2022 | 17/6/2026 | A vulnerability was found in starter-public-edition-4 up to 4.6.10. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 4.6.11 is able to address this issue. The name of the patch is… | |
| Modificada | Alta (7.8) | 0.21% | — | Siemens Star-ccm+ | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges. | |
| Modificada | Alta (7.8) | 0.19% | — | HP Jumpstart | 12/12/2022 | 17/6/2026 | A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software. | |
| Modificada | Media (5.4) | 0.50% | — | Dinstar Dag2000-16o Firmware | 28/11/2022 | 17/6/2026 | Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (6.1) | 0.55% | — | Fivestarplugins Five Star Restaurant Reservations | 21/11/2022 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could… |