Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.46% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+8 | 21/12/2022 | 17/6/2026 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets. | |
| Modificada | Alta (7.5) | 0.59% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+8 | 21/12/2022 | 17/6/2026 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an attacker to access the device’s main management page from the cloud. This feature enables users to remotely connect devices, however, the current implementation permits users to access other device's… | |
| Modificada | Media (5.3) | 0.49% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+8 | 21/12/2022 | 17/6/2026 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensitive data concerning the device. | |
| Modificada | Crítica (9.8) | 12% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+8 | 21/12/2022 | 17/6/2026 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory. | |
| Modificada | Crítica (9.8) | 1.6% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+8 | 21/12/2022 | 17/6/2026 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability. | |
| Modificada | Crítica (9.8) | 1.5% | 💥 PoC | Codecentric Spring Boot Admin | 9/12/2022 | 17/6/2026 | Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent… | |
| Modificada | Crítica (9.8) | 1.4% | — | Hope-boot Project Hope-boot | 7/12/2022 | 17/6/2026 | hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE). | |
| Modificada | Alta (7.2) | 0.85% | — | Maku-boot | 7/12/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects the function doExecute of the file AbstractScheduleJob.java of the component Scheduled Task Handler. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.2) | 0.75% | — | Jrecms Springbootcms | 5/12/2022 | 17/6/2026 | A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functionality of the component Template Management. The manipulation leads to injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214790 is the… | |
| Modificada | Media (4.3) | 0.53% | — | Jeecg Boot | 25/11/2022 | 9/7/2026 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin. | |
| Modificada | Media (4.3) | 0.53% | — | Jeecg Boot | 25/11/2022 | 9/7/2026 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin. | |
| Modificada | Crítica (9.8) | 0.98% | — | Jeecg Boot | 25/11/2022 | 9/7/2026 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString. | |
| Modificada | Crítica (9.8) | 0.78% | — | Jeecg Boot | 25/11/2022 | 9/7/2026 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check. | |
| Modificada | Media (5.3) | 0.63% | — | Jeecg Boot | 25/11/2022 | 9/7/2026 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. | |
| Modificada | Alta (7.5) | 2.7% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+5 | 9/11/2022 | 17/6/2026 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote… | |
| Modificada | Crítica (9.8) | 2.6% | 💥 PoC | Vmware Bosh EditorVmware Cloudfoundry Manifest YML SupportVmware Concourse CI Pipeline EditorVmware Spring Boot Tools+1 | 4/11/2022 | 17/6/2026 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the… | |
| Modificada | Crítica (9.1) | 0.84% | — | Silabs Gecko Bootloader | 2/11/2022 | 17/6/2026 | Out-of-Bounds error in GBL parser in Silicon Labs Gecko Bootloader version 4.0.1 and earlier allows attacker to overwrite flash Sign key and OTA decryption key via malicious bootloader upgrade. | |
| Modificada | Baja (3.7) | 2.4% | — | Haxx CurlNetapp Clustered Data OntapNetapp Element SoftwareNetapp HCI Management Node+9 | 23/9/2022 | 17/6/2026 | When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings. | |
| Modificada | Alta (7.1) | 0.58% | — | Denx U-boot | 23/9/2022 | 17/6/2026 | There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a… | |
| Modificada | Media (6.7) | 0.85% | 💥 PoC | Eurosoft-uk Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+6 | 26/8/2022 | 17/6/2026 | A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader.… | |
| Modificada | Media (6.7) | 1.1% | 💥 PoC | Horizondatasys Uefi BootloaderRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+6 | 26/8/2022 | 17/6/2026 | A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this… | |
| Modificada | Media (6.5) | 1.7% | — | GnutlsRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+1 | 24/8/2022 | 17/6/2026 | A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances. | |
| Modificada | Media (6.1) | 0.59% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 18/8/2022 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php. | |
| Modificada | Crítica (9.8) | 0.80% | — | Jeecg Boot | 4/8/2022 | 17/6/2026 | A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of the file /api/. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205594 is the… | |
| Modificada | Media (6.5) | 1.3% | — | Clusterlabs BoothDebian LinuxFedoraproject Fedora | 28/7/2022 | 17/6/2026 | The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster. |