Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.98% | — | Livebook | 22/6/2023 | 17/6/2026 | Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a `livebook://` link from a browser which opens Livebook Desktop and triggers arbitrary code execution on victim's machine. Any user using Livebook Desktop on Windows is potentially vulnerable to… | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Crítica (9.8) | 0.94% | — | Loka Solive | 30/5/2023 | 17/6/2026 | SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened. Depending on how the data is… | |
| Modificada | Alta (7.5) | 0.78% | — | Loka Solive | 30/5/2023 | 17/6/2026 | SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened. When an attacker injects too… | |
| Modificada | Alta (7.8) | 0.80% | — | Luatex Project LuatexMiktexTUG TEX Live | 20/5/2023 | 17/6/2026 | LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5. | |
| Modificada | Media (4.8) | 0.37% | — | Formilla Live Chat | 16/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Formilla Live Chat by Formilla plugin <= 1.3 versions. | |
| Modificada | Crítica (9.8) | 1.9% | — | Catontechnology Caton Live | 12/5/2023 | 17/6/2026 | A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/ping.cgi of the component Mini_HTTPD. The manipulation of the argument address with the input ;id;uname${IFS}-a leads to command injection. The attack may be initiated… | |
| Modificada | Media (5.5) | 0.37% | — | Luatex Project LuatexMiktexTUG TEX Live | 11/5/2023 | 17/6/2026 | LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5. | |
| Modificada | Media (4.8) | 0.44% | — | Byconsole Pickup | Delivery | Dine-in Date Time | 8/5/2023 | 17/6/2026 | The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 4.9% | 💥 Exploit | WP Live Chat Shoutbox Project WP Live Chat Shoutbox | 24/4/2023 | 17/6/2026 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Media (6.1) | 0.46% | — | WP Live Chat Shoutbox Project WP Live Chat Shoutbox | 24/4/2023 | 17/6/2026 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins. | |
| Modificada | Media (4.8) | 0.39% | — | Wp-olivecart Project Wp-olivecart | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Olive Design WP-OliveCart plugin <= 1.1.3 versions. | |
| Modificada | Media (6.5) | 0.71% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation… | |
| Modificada | Alta (8.8) | 0.96% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /settings/guest-settings endpoint, the /settings/samlusers-settings endpoint, and the /settings/users-settings endpoint. A malicious user (already… | |
| Modificada | Media (6.5) | 0.72% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in the OnlyOffice backend of other users by guessing the file ID of a target file. | |
| Modificada | Crítica (9.8) | 1.0% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and can be bypassed by passing any string… | |
| Modificada | Crítica (9.8) | 1.0% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding… | |
| Modificada | Media (6.5) | 0.44% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user. | |
| Modificada | Media (5.5) | 0.34% | — | Kyocera Mobile PrintTriumph-adler Mobile PrintOlivetti Mobile Print | 13/4/2023 | 17/6/2026 | KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is installed on the victim user's Android device, the app may send an intent and direct the affected… | |
| Modificada | Media (5.4) | 0.52% | — | Liveaction Livesp | 12/4/2023 | 9/7/2026 | A stored HTML injection vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary code via a crafted payload. | |
| Modificada | Alta (7.8) | 0.18% | — | Wolt Delivery | 11/4/2023 | 17/6/2026 | Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineering the application binary. | |
| Modificada | Media (5.4) | 0.45% | — | Liveaction Livesp | 10/4/2023 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Crítica (9.8) | 1.4% | — | Adobe Livecycle ES4 | 6/4/2023 | 17/6/2026 | A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially crafted Java serialized objects to a specific URL. Adobe LiveCycle ES4 version 11.0.1 and later may be vulnerable if the… | |
| Modificada | Alta (7.5) | 0.51% | — | 3DS Enovia Live Collaboration | 9/3/2023 | 17/6/2026 | An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server. | |
| Modificada | Crítica (9.8) | 0.95% | — | 3DS Enovia Live Collaboration | 9/3/2023 | 17/6/2026 | An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution. |