Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.58% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The… | |
| Modificada | Alta (7.8) | 0.62% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_B files. The… | |
| Modificada | Alta (7.8) | 0.54% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The… | |
| Modificada | Alta (7.8) | 0.48% | — | Ansys Spaceclaim | 15/9/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The… | |
| Analizada | Alta (8.1) | 18% | ⚠ Explotación activa | Acclaimsystems Usaherds | 21/12/2021 | 17/6/2026 | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. | |
| Modificada | Media (4.3) | 1.6% | — | Jenkins Claim | 24/2/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change claims. | |
| Modificada | Media (5.4) | 9.4% | — | Jenkins Claim | 24/2/2021 | 17/6/2026 | Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers who are able to control the display names of Jenkins users, either via the security realm, or directly inside Jenkins. | |
| Modificada | Crítica (9.8) | 1.4% | — | Youracclaim Acclaim | 23/8/2019 | 17/6/2026 | The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records. | |
| Modificada | Alta (7.5) | 7.9% | — | Christianwebministries Proclaim | 22/2/2018 | 17/6/2026 | Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. | |
| Modificada | Crítica (9.8) | 8.1% | — | Christianwebministries Proclaim | 22/2/2018 | 17/6/2026 | Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. |