Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.6%—Cisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Event CenterCisco Webex Meeting Center+226/11/201917/6/2026
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could…
ModificadaMedia (6.5)1.6%—Jenkins Support Core21/11/201917/6/2026
A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master.
ModificadaMedia (6.5)0.71%—Jenkins Support Core21/11/201917/6/2026
A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete support bundles.
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaMedia (4.3)1.3%—Atlassian Troubleshooting AND SupportAtlassian BambooAtlassian BitbucketAtlassian Confluence+48/11/201917/6/2026
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the…
ModificadaMedia (5.4)0.78%—Solaplugins Sola Support Tickets20/9/201917/6/2026
The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS.
ModificadaCrítica (9.8)18%—Haxx CurlFedoraproject FedoraOpensuse LeapNetapp Cloud Backup+1316/9/201917/6/2026
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
ModificadaCrítica (9.8)7.5%—Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Steelstore+816/9/201917/6/2026
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
ModificadaMedia (6.1)1.1%—Supportflow Project Supportflow16/9/201917/6/2026
The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt.
ModificadaMedia (6.1)1.0%—Supportflow Project Supportflow16/9/201917/6/2026
The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title.
ModificadaMedia (6.1)0.91%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
ModificadaCrítica (9.8)2.0%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
ModificadaMedia (6.1)0.91%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
ModificadaCrítica (9.1)2.5%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
ModificadaCrítica (9.8)2.2%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
ModificadaMedia (5.3)1.3%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
ModificadaCrítica (9.8)1.8%—Wpsupportplus WP Support Plus Responsive Ticket System22/8/201917/6/2026
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
ModificadaAlta (7.5)1.4%—Getawesomesupport Awesome Support20/8/201917/6/2026
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
ModificadaMedia (6.1)0.91%—Getawesomesupport Awesome Support20/8/201917/6/2026
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
ModificadaAlta (7.8)0.35%—Intel Driver & Support Assistant19/8/201917/6/2026
Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Intel Driver & Support Assistant19/8/201917/6/2026
Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.2)1.3%—Oracle Isupport23/7/201917/6/2026
Vulnerability in the Oracle iSupport component of Oracle E-Business Suite (subcomponent: Service Requests). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport.…
ModificadaAlta (7.8)0.69%—Haxx CurlOracle Enterprise Manager OPS CenterOracle Http ServerOracle Mysql Server+52/7/201917/6/2026
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
ModificadaAlta (7.8)2.2%—Pc-doctor ToolboxDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS25/6/201917/6/2026
PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.
ModificadaAlta (7.8)1.6%💥 PoCHP Support Assistant25/6/201917/6/2026
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.