Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fsm10056 FirmwareQualcomm Ipq5010 Firmware+132 | 5/9/2023 | 17/6/2026 | Memory corruption in Core Platform while printing the response buffer in log. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Alta (8.8) | 0.63% | — | Dell Powerscale Onefs | 29/8/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Modificada | Crítica (9.8) | 0.78% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution. | |
| Modificada | Alta (7.1) | 0.15% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files. | |
| Modificada | Media (6.5) | 0.40% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, to bypass mode protections and gain elevated privileges. | |
| Modificada | Media (4.3) | 0.38% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service, code execution and information disclosure. | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low privilege local attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Modificada | Media (6.7) | 0.17% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also. | |
| Modificada | Alta (7.1) | 0.11% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 Firmware+181 | 8/8/2023 | 17/6/2026 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. | |
| Modificada | Media (5.4) | 0.49% | — | Fsmlabs Timekeeper | 26/7/2023 | 17/6/2026 | An XSS issue was discovered in FSMLabs TimeKeeper 8.0.17. On the "Configuration -> Compliance -> Add a new compliance report" and "Configuration -> Timekeeper Configuration -> Add a new source there" screens, there are entry points to inject JavaScript code. | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Fsmlabs Timekeeper | 26/7/2023 | 17/6/2026 | An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to… | |
| Modificada | Media (5.5) | 0.21% | — | Edinet-fsa Xbrl Data Create | 19/7/2023 | 17/6/2026 | XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker. | |
| Modificada | Alta (8.8) | 0.65% | — | Wolfssl | 17/7/2023 | 17/6/2026 | If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the session master secret. Using a potentially known IKM value when generating the… | |
| Modificada | Alta (7.8) | 0.31% | — | Lcdf Gifsicle | 23/6/2023 | 17/6/2026 | Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c. | |
| Modificada | Crítica (9.8) | 6.0% | 💥 PoC | Zohocorp Manageengine Adselfservice Plus | 20/6/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail… | |
| Modificada | Media (6.5) | 0.54% | — | Pivotal Cloud Foundry NFS VolumePivotal Cloud Foundry NotificationsPivotal Cloud Foundry SMB Volume | 16/6/2023 | 17/6/2026 | Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19. | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+953 | 14/6/2023 | 17/6/2026 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. | |
| Modificada | Alta (7.8) | 1.3% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+238 | 6/6/2023 | 17/6/2026 | Memory corruption due to double free in Core while mapping HLOS address to the list. | |
| Modificada | Media (5.5) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+344 | 6/6/2023 | 17/6/2026 | information disclosure due to cryptographic issue in Core during RPMB read request. | |
| Modificada | Alta (7.8) | 0.71% | — | Erofs-utils Project Erofs-utils | 1/6/2023 | 17/6/2026 | Heap Buffer Overflow in the erofs_read_one_data function at data.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image. |