Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1459 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.28% | — | Miniupnp Project Ngiflib | 19/7/2023 | 17/6/2026 | ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c. | |
| Modificada | Media (6) | 0.21% | — | Oracle Hyperion Essbase Administration Services | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion… | |
| Modificada | Alta (8.8) | 0.96% | 💥 PoC | Miniorange Oauth Single Sign ON | 18/7/2023 | 17/6/2026 | Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3. | |
| Modificada | Alta (7.5) | 2.0% | — | ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+2 | 17/7/2023 | 17/6/2026 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | |
| Modificada | Media (6.5) | 0.62% | — | Miniupnp Project Ngiflib | 17/7/2023 | 17/6/2026 | An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_file2_0 | |
| Modificada | Media (6.8) | 0.22% | — | Espressif Esp32-d0wd-v3 FirmwareEspressif Esp32-d0wdr2-v3 FirmwareEspressif Esp32-u4wdh FirmwareEspressif Esp32-pico-v3 Firmware+18 | 17/7/2023 | 17/6/2026 | An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the… | |
| Modificada | Media (5.3) | 0.62% | — | OpensslManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration Utility | 14/7/2023 | 17/6/2026 | Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding… | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Carel Boss Mini Firmware | 12/7/2023 | 17/6/2026 | A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.8) | 0.32% | — | Loxone Miniserver GO GEN 2 Firmware | 5/7/2023 | 17/6/2026 | Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo configuration. This allows the elevated execution of binaries without a password requirement. | |
| Modificada | Alta (7.8) | 0.29% | — | Loxone Miniserver GO GEN 2 Firmware | 5/7/2023 | 17/6/2026 | The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password and escalate privileges. | |
| Modificada | Alta (7.2) | 1.4% | — | Loxone Miniserver GO GEN 2 Firmware | 5/7/2023 | 17/6/2026 | The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter. | |
| Modificada | Media (4.3) | 0.39% | — | Amministrazione Trasparente Project Amministrazione Trasparente | 1/7/2023 | 17/6/2026 | The Amministrazione Trasparente plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1. This is due to missing or incorrect nonce validation on the at_save_aturl_meta() function. This makes it possible for unauthenticated attackers to update meta data via a forged… | |
| Modificada | Alta (7) | 0.13% | — | HP 260 G4 Desktop Mini FirmwareHP T430 FirmwareHP T628 FirmwareHP 240 G10 Firmware+55 | 30/6/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Miniorange Web3 - Crypto Wallet Login & NFT Token Gating | 30/6/2023 | 17/6/2026 | The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user… | |
| Modificada | Alta (7.5) | 0.53% | — | Miniorange Active Directory Integration / Ldap Integration | 29/6/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to… | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 29/6/2023 | 17/6/2026 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for… | |
| Modificada | Alta (7.5) | 0.50% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Alta (7.2) | 1.3% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. | |
| Modificada | Alta (8.1) | 0.55% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. | |
| Modificada | Media (5.4) | 0.41% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Media (5.4) | 0.40% | — | Geminilabs Site Reviews | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | |
| Modificada | Baja (2.4) | 0.36% | — | Dominionvoting Democracy Suite | 19/6/2023 | 17/6/2026 | A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in which ballots were cast from public ballot-level data, allowing deanonymization of voted ballots, in several types of scenarios. This issue… | |
| Modificada | Alta (8.8) | 0.87% | — | Minical | 18/6/2023 | 17/6/2026 | A vulnerability was found in miniCal 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /booking/show_bookings/. The manipulation of the argument search_query leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… |