Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 33% | 💥 PoC | Dolibarr Erp/crm | 1/11/2023 | 17/6/2026 | Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code. | |
| Modificada | Media (4.8) | 0.46% | — | Dolibarr Erp/crm | 30/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5. | |
| Modificada | Alta (7.5) | 0.78% | — | Elastic Kibana | 26/10/2023 | 17/6/2026 | An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this… | |
| Modificada | Media (5.4) | 0.66% | 💥 PoC | Tribalsystems Zenario | 25/10/2023 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias. | |
| Modificada | Alta (8.8) | 0.59% | — | Wazuh-dashboardWazuh-kibana-app | 9/10/2023 | 17/6/2026 | Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their… | |
| Modificada | Media (5.4) | 0.57% | 💥 PoC | Tribalsystems Zenario | 6/10/2023 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout. | |
| Modificada | Media (5.4) | 0.59% | 💥 PoC | Tribalsystems Zenario | 6/10/2023 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias. | |
| Modificada | Media (6.1) | 0.44% | — | Dolibarr Erp/crm | 1/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0. | |
| Modificada | Crítica (9.6) | 1.3% | — | Dolibarr Erp/crm | 20/9/2023 | 9/7/2026 | Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject. | |
| Modificada | Alta (8.8) | 1.5% | — | Dolibarr Erp/crm | 20/9/2023 | 9/7/2026 | File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions. | |
| Modificada | Alta (7.2) | 32% | — | Dolibarr Erp/crm | 20/9/2023 | 9/7/2026 | An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script. | |
| Modificada | Media (4.8) | 0.44% | — | Tribalsystems Zenario | 28/8/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field. | |
| Modificada | Alta (7.5) | 0.80% | — | Alibaba Tengine | 22/8/2023 | 17/6/2026 | The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests. | |
| Modificada | Alta (8.8) | 1.3% | — | Alibabacloud Nacos Spring Project | 21/8/2023 | 17/6/2026 | An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component. | |
| Modificada | Alta (7.5) | 0.94% | — | Fujifilm Docuprint M265 Z FirmwareFujifilm Docuprint M268 Z FirmwareFujifilm Docuprint M225 Z FirmwareFujifilm Docuprint M225 DW Firmware+212 | 11/7/2023 | 17/6/2026 | Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information… | |
| Modificada | Media (6.5) | 0.60% | — | Fibaro Fgms-001 Firmware | 20/6/2023 | 17/6/2026 | A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Dolibarr Erp/crm | 13/6/2023 | 17/6/2026 | An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists. | |
| Modificada | Alta (8.8) | 82% | 💥 Exploit | Dolibarr Erp/crm | 29/5/2023 | 17/6/2026 | Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data. | |
| Modificada | Media (5.3) | 0.19% | — | Libarchive | 29/5/2023 | 17/6/2026 | Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to… | |
| Modificada | Alta (8.8) | 0.96% | — | Elastic Kibana | 4/5/2023 | 17/6/2026 | Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process. | |
| Modificada | Alta (8.8) | 0.60% | — | Elastic Kibana | 4/5/2023 | 17/6/2026 | Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of… | |
| Modificada | Media (6.5) | 0.65% | — | Budibase | 6/4/2023 | 17/6/2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to Server-Side Request Forgery. This can lead to an attacker gaining access to a Budibase AWS secret key. Users of Budibase cloud need to take no action. Self-host users who… | |
| Modificada | Crítica (9.8) | 0.60% | — | Atm-consulting Dolibarr Module Quicksupplierprice | 20/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version… | |
| Modificada | Media (6.1) | 0.52% | — | Elastic Kibana | 22/2/2023 | 17/6/2026 | An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL. | |
| Modificada | Media (6.5) | 0.89% | — | Decode-uri-component Project Decode-uri-componentElastic Kibana | 8/2/2023 | 17/6/2026 | A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process. |