Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.17% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+18 | 22/5/2023 | 17/6/2026 | The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device could compromise other devices connected to the user's cloud. | |
| Modificada | Media (5.3) | 0.75% | — | Spring-boot-actuator-logview Project Spring-boot-actuator-logview | 11/5/2023 | 17/6/2026 | spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view. | |
| Modificada | Media (6.7) | 0.16% | — | Intel ONE Boot Flash Update | 10/5/2023 | 17/6/2026 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel ONE Boot Flash Update | 10/5/2023 | 17/6/2026 | Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access | |
| Modificada | Media (5.4) | 0.40% | — | Pearadmin Pear Admin Boot | 25/4/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title of a private message. | |
| Modificada | Crítica (9.8) | 1.1% | — | Vmware Spring Boot | 20/4/2023 | 17/6/2026 | In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to… | |
| Modificada | Media (6.1) | 0.43% | — | Jbootfly Project Jbootfly | 18/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Jbootfly allows attackers to obtain sensitive information via the username parameter. | |
| Modificada | Crítica (9.8) | 1.00% | — | Jeecg Boot | 31/3/2023 | 17/6/2026 | A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated… | |
| Modificada | Crítica (9.8) | 0.82% | — | Jeecg Boot | 30/3/2023 | 17/6/2026 | A vulnerability was found in jeecg-boot 3.5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file SysDictMapper.java of the component Sleep Command Handler. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 36% | 💥 Exploit | Jeecg Boot | 17/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 2.3% | — | Openbsd OpensshNetapp Brocade Fabric Operating SystemNetapp HCI Bootstrap OSNetapp Solidfire Element OS | 17/3/2023 | 14/7/2026 | ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. | |
| Modificada | Alta (7.5) | 0.60% | — | Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+6 | 23/2/2023 | 17/6/2026 | The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol. | |
| Modificada | Media (5.4) | 0.70% | — | Bootstrapped Easy Affiliate Links | 21/2/2023 | 17/6/2026 | The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.47% | — | Bootstrap Shortcodes Project Bootstrap Shortcodes | 21/2/2023 | 17/6/2026 | The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.5) | 0.31% | 💥 PoC | Intel ONE Boot Flash Update | 16/2/2023 | 17/6/2026 | Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 1.2% | — | Pbootcms | 3/2/2023 | 17/6/2026 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request. | |
| Modificada | Media (5.4) | 0.53% | — | CPT Bootstrap Carousel Project CPT Bootstrap Carousel | 30/1/2023 | 17/6/2026 | The CPT Bootstrap Carousel WordPress plugin through 1.12 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Alta (7.5) | 0.93% | — | Carel Pcoweb Card WEBCarel Pcoweb Card BiosCarel Pcoweb Card Boot | 26/1/2023 | 17/6/2026 | An issue was discovered in Rehau devices that use a pCOWeb card BIOS v6.27, BOOT v5.00, web version v2.2, allows attackers to gain full unauthenticated access to the configuration and service interface. | |
| Modificada | Media (5.4) | 0.47% | — | Easy Bootstrap Shortcode Project Easy Bootstrap Shortcode | 23/1/2023 | 17/6/2026 | The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Media (6.1) | 0.61% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 20/1/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Jeecg Boot | 19/1/2023 | 17/6/2026 | Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. | |
| Modificada | Alta (7.5) | 1.6% | — | Apache ShiroVmware Spring Boot | 14/1/2023 | 17/6/2026 | When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching.… | |
| Modificada | Media (5.4) | 0.53% | — | Bootstrapped WP Recipe Maker | 9/1/2023 | 17/6/2026 | The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.3) | 0.50% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+8 | 21/12/2022 | 17/6/2026 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script could use parameters from a HTTP request to create a URL capable of changing the host parameter. The changed host parameter in the HTTP could point to another host that will send a request to the host or… | |
| Modificada | Media (5.3) | 0.53% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+8 | 21/12/2022 | 17/6/2026 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the latest actions completed by specific users. |