Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
815 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.15% | — | SAP S4coreSAP Vendor Master Hierarchy | 9/5/2023 | 17/6/2026 | Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to… | |
| Modificada | Alta (7.1) | 0.74% | — | Dualspace Lock Master | 14/4/2023 | 17/6/2026 | An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludashi.superlock.util.pref.SharedPrefProviderEntryMethod: insert of the android.net.Uri.insert method. | |
| Modificada | Alta (7.8) | 0.31% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution. | |
| Modificada | Alta (8.8) | 0.65% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation. | |
| Modificada | Alta (8.8) | 0.83% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.1% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation. | |
| Modificada | Alta (8.8) | 1.6% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution. | |
| Modificada | Crítica (9.8) | 1.1% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator. | |
| Modificada | Alta (8.8) | 1.3% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution. | |
| Modificada | Alta (7.5) | 0.57% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials. | |
| Modificada | Alta (8.8) | 0.55% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation. | |
| Modificada | Alta (7.5) | 0.74% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass. | |
| Modificada | Alta (7.8) | 0.16% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation. | |
| Modificada | Alta (8.8) | 0.66% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary… | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Joommasters JMS Blog | 23/3/2023 | 17/6/2026 | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Media (4.8) | 0.37% | — | Wp-master Feed Changer & Remover | 20/3/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions. | |
| Modificada | Alta (7.8) | 0.22% | — | AMD Ryzen Master | 1/3/2023 | 17/6/2026 | Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user. | |
| Modificada | Alta (8.8) | 0.38% | — | Expresstech Quiz AND Survey Master | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions. | |
| Analizada | Alta (7.5) | 83% | ⚠ Explotación activa💥 Exploit | Terra-master Terramaster Operating System | 7/2/2023 | 17/6/2026 | TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response. | |
| Modificada | Alta (8.8) | 0.99% | — | Deltaww Infrasuite Device Master | 26/1/2023 | 17/6/2026 | A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an… | |
| Modificada | Media (6.1) | 0.53% | — | Wp-master Pardakht-delkhah | 23/1/2023 | 17/6/2026 | The پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenticated attackers to send a request with XSS payloads, which will be triggered when a high privilege users such as admin visits a page from the plugin. | |
| Modificada | Crítica (9.8) | 0.61% | — | Ton-masterserver Project Ton-masterserver | 13/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in GGGGGGGG ToN-MasterServer. Affected by this issue is some unknown functionality of the file public_html/irc_updater/svr_request_pub.php. The manipulation leads to sql injection. The patch is identified as 3a4c7e6d51bf95760820e3245e06c6e321a7168a. It… | |
| Modificada | Alta (8.8) | 1.0% | — | Deltaww Infrasuite Device Master | 13/1/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-DataCollect service port without proper verification. An attacker could provide malicious serialized objects to execute arbitrary code upon deserialization. | |
| Modificada | Media (6.5) | 0.37% | — | Master-quiz Project Master-quiz | 14/12/2022 | 17/6/2026 | An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3. An attacker can continue the quiz of a different user. In doing so, the attacker can view that user's answers and modify those answers. |