Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Starwindsoftware NASStarwindsoftware SAN | 6/2/2022 | 17/6/2026 | A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges. This… | |
| Modificada | Alta (8.8) | 0.89% | — | Starwindsoftware NASStarwindsoftware SAN | 6/2/2022 | 17/6/2026 | A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (including system/administrator user) using any available user This affects StarWind SAN and NAS v0.2 build 1633. | |
| Modificada | Crítica (9.8) | 1.2% | — | Starwindsoftware Iscsi SAN | 6/2/2022 | 16/6/2026 | A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target multiple times. This affects iSCSI SAN (Windows Native) Version 6.0, build… | |
| Modificada | Alta (7.5) | 1.1% | — | Starwindsoftware Iscsi SAN | 6/2/2022 | 16/6/2026 | A flaw was found in StarWind iSCSI target. An attacker could script standard iSCSI Initiator operation(s) to exhaust the StarWind service socket, which could lead to denial of service. This affects iSCSI SAN (Windows Native) Version 3.2.2 build 2007-02-20. | |
| Modificada | Media (6.1) | 0.80% | — | YET Another Stars Rating Project YET Another Stars Rating | 4/2/2022 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9.9), vulnerable at parameter 'source'. | |
| Modificada | Media (5.3) | 1.8% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host of the web application. | |
| Modificada | Alta (7.5) | 0.81% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP. | |
| Modificada | Crítica (9.8) | 1.7% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication. | |
| Modificada | Alta (7.5) | 1.8% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application. | |
| Modificada | Media (6.5) | 0.81% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request. | |
| Modificada | Crítica (9.8) | 3.6% | — | Globalnorthstar Northstar Club Management | 4/2/2022 | 17/6/2026 | Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters. | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+26 | 28/1/2022 | 15/8/2026 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends… | |
| Modificada | Media (5.4) | 0.61% | — | Fivestarplugins Five Star Restaurant Reservations | 24/1/2022 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting… | |
| Modificada | Alta (8.8) | 1.1% | — | Starwindsoftware Command Center | 24/1/2022 | 17/6/2026 | A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects StarWind Command Center build 6003 v2. | |
| Modificada | Crítica (9.8) | 1.2% | — | Starwind Command CenterStarwind San&nas | 4/1/2022 | 17/6/2026 | A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864. | |
| Modificada | Alta (7.5) | 1.6% | — | Stars Rating Project Stars Rating | 3/1/2022 | 17/6/2026 | The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated. | |
| Modificada | Alta (7.8) | 0.79% | 💥 PoC | Biostar Racing GT EVO | 1/1/2022 | 17/6/2026 | An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the driver's device object and issue IOCTLs to read or write to arbitrary physical memory locations (or call an arbitrary address), leading to execution of arbitrary code. This is associated with 0x226040,… | |
| Modificada | Alta (7.2) | 1.5% | — | Starfish Rich Review | 27/12/2021 | 17/6/2026 | The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue | |
| Modificada | Alta (8.8) | 0.46% | — | Starcharge Titan 180 Premium FirmwareStarcharge Nova 360 Cabinet Firmware | 22/12/2021 | 9/7/2026 | Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9. | |
| Modificada | Alta (8.8) | 1.8% | — | Starcharge Titan 180 Premium FirmwareStarcharge Nova 360 Cabinet Firmware | 22/12/2021 | 9/7/2026 | Certain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet <=1.3.0.0.6 - Fixed: 1.3.0.0.9 and Titan 180 Premium <=1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0. | |
| Modificada | Alta (7.5) | 0.58% | — | Listary | 14/12/2021 | 17/6/2026 | An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package validation, it can lead to manipulation of update packages that… | |
| Modificada | Alta (7.5) | 1.3% | — | Bopsoft Listary | 14/12/2021 | 17/6/2026 | An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user that runs via Listary). | |
| Modificada | Alta (7.3) | 0.55% | — | Bopsoft Listary | 14/12/2021 | 17/6/2026 | An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the attacker will be able to duplicate the victim's token to impersonate… | |
| Modificada | Alta (7.8) | 0.84% | — | Siemens Simcenter Star-ccm+ Viewer | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < 2021.3.1). The starview+.exe application lacks proper validation of user-supplied data when parsing scene files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this… | |
| Modificada | Crítica (9.8) | 18% | — | Mozilla NSSMozilla NSS ESRNetapp Cloud BackupNetapp E-series Santricity OS Controller+6 | 8/12/2021 | 17/6/2026 | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate… |