Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.51% | — | Nextcloud Deck | 18/1/2024 | 17/6/2026 | Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is recommended that the Nextcloud Deck is… | |
| Modificada | Crítica (9.8) | 0.76% | — | Nextcloud Global Site Selector | 18/1/2024 | 17/6/2026 | Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud Global Site Selector is upgraded to version… | |
| Modificada | Alta (7.2) | 0.58% | — | Posimyth Nexter Extension | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in POSIMYTH Nexter Extension.This issue affects Nexter Extension: from n/a through 2.0.3. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Nextcloud Server | 22/12/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when a (reverse) proxy is configured as trusted proxy the server… | |
| Modificada | Media (5.4) | 0.61% | — | Nextcloud Server | 22/12/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when an attacker manages to get access to an active session of… | |
| Modificada | Media (4.3) | 0.29% | — | Nextcloud | 22/12/2023 | 17/6/2026 | The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior to version 4.9.2, the application can be used without providing the 4 digit PIN code. Nextcloud iOS Files app should be upgraded to 4.9.2 to receive the patch. No known workarounds are available. | |
| Modificada | Media (6.5) | 0.55% | — | Nextcloud Calendar | 22/12/2023 | 17/6/2026 | Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3 | |
| Modificada | Media (6.1) | 0.40% | — | Nextscripts Social Networks Auto Poster | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social Networks Auto-Poster: from n/a through 4.4.2. | |
| Modificada | Media (6.5) | 0.62% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail deliver-related URL. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial… | |
| Modificada | Media (6.5) | 0.62% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special URL. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary PHP file with .asp file extension under specific system paths, to access and modify partial system… | |
| Modificada | Alta (8) | 0.68% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a localhost can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or… | |
| Modificada | Media (5.3) | 0.60% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response. | |
| Modificada | Alta (7.5) | 1.3% | — | Softnext Mail SQR Expert | 15/12/2023 | 17/6/2026 | Softnext Mail SQR Expert has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files. | |
| Modificada | Media (6.5) | 0.31% | — | Phoenixcontact AXC F 1152 FirmwarePhoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 3152 FirmwarePhoenixcontact BPC 9102s Firmware+5 | 14/12/2023 | 17/6/2026 | A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices. | |
| Modificada | Alta (8.8) | 0.74% | — | Phoenixcontact AXC F 1152 FirmwarePhoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 3152 FirmwarePhoenixcontact BPC 9102s Firmware+5 | 14/12/2023 | 17/6/2026 | A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices. | |
| Modificada | Alta (8.8) | 0.96% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+7 | 5/12/2023 | 17/6/2026 | A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device. | |
| Modificada | Alta (8.8) | 0.27% | — | Imagely Nextgen Gallery | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37. | |
| Modificada | Crítica (9.8) | 0.87% | — | Nextcloud Mail | 21/11/2023 | 17/6/2026 | Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotected endpoint in the Mail app to perform a SSRF attack. Nextcloud Mail app versions 2.2.8 and 3.3.0 contain a patch for this issue. As a… | |
| Modificada | Crítica (9.8) | 0.80% | — | Nextcloud Server | 21/11/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, and 27.1.0 of Nextcloud… | |
| Modificada | Media (4.4) | 0.25% | — | Nextcloud Server | 21/11/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and Nextcloud Enterprise Server, when the log level was set to debug, the user_ldap app logged user passwords in plaintext into the log… | |
| Modificada | Media (4.3) | 0.60% | — | Nextcloud Server | 21/11/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, and 27.1.0 of Nextcloud… | |
| Modificada | Baja (2.7) | 0.67% | — | Nextcloud Server | 21/11/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and Nextcloud Enterprise Server, admins can change authentication details of user configured external storage. Nextcloud Server and… | |
| Modificada | Media (5.4) | 0.57% | — | Nextcloud Server | 21/11/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, when a user is tricked into copy pasting HTML code without markup (Ctrl+Shift+V) the markup will… | |
| Modificada | Media (5.4) | 0.64% | — | Nextcloud Server | 21/11/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, an attacker could insert links into circles name that would be opened when clicking the circle name in a… | |
| Modificada | Alta (7.1) | 0.95% | — | Nextcloud Server | 21/11/2023 | 17/6/2026 | Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and starting in version 20.0.0 and prior to versions 20.0.14.16, 21.0.9.13, 22.2.10.15, 23.0.12.12, 24.0.12.8, 25.0.13, 26.0.8, and… |