Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 2/8/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (8) | 1.3% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Privilege Escalation to root administrator (nsroot) | |
| Modificada | Media (6.1) | 2.6% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 5/8/2026 | Unauthenticated remote code execution | |
| Modificada | Media (6.5) | 0.96% | — | Weave Gitops Terraform Controller | 14/7/2023 | 17/6/2026 | Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave GitOps Terraform Controller which could allow an authenticated remote attacker to view sensitive information. This vulnerability stems from… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Citrix Sharefile Storage Zones Controller | 10/7/2023 | 17/6/2026 | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | |
| Modificada | Media (6.1) | 81% | 💥 Exploit | Citrix GatewayCitrix Application Delivery Controller | 10/7/2023 | 17/6/2026 | Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | |
| Modificada | Alta (7.5) | 1.1% | — | Citrix Application Delivery ControllerCitrix Gateway | 10/7/2023 | 17/6/2026 | Arbitrary file read in Citrix ADC and Citrix Gateway | |
| Modificada | Media (4.8) | 0.39% | — | Plainware Shiftcontroller | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Plainware ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions. | |
| Modificada | Alta (7.5) | 0.88% | — | Synology Diskstation Manager Unified ControllerSynology Router ManagerSynology Diskstation Manager | 13/6/2023 | 17/6/2026 | Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors. | |
| Modificada | Alta (8.1) | 0.97% | — | Synology Diskstation Manager Unified ControllerSynology Router ManagerSynology Diskstation Manager | 13/6/2023 | 17/6/2026 | Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.1) | 0.44% | — | Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux | 9/6/2023 | 17/6/2026 | A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | |
| Modificada | Media (6.1) | 0.43% | — | Plainware Shiftcontroller | 9/6/2023 | 17/6/2026 | The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the query string in versions up to, and including, 4.9.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Crítica (9.8) | 0.50% | — | Gallagher Controller 6000 Firmware | 1/6/2023 | 17/6/2026 | Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and prior. | |
| Modificada | Alta (7.8) | 1.4% | 💥 PoC | Linux KernelNetapp HCI Baseboard Management Controller | 1/6/2023 | 17/6/2026 | A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 15/5/2023 | 17/6/2026 | In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise. | |
| Modificada | Media (5.3) | 1.1% | 💥 PoC | Cassianetworks Access Controller | 11/5/2023 | 17/6/2026 | Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users. | |
| Modificada | Alta (7.8) | 13% | 💥 PoC | Linux KernelRedhat Enterprise LinuxNetapp HCI Baseboard Management Controller | 8/5/2023 | 17/6/2026 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled. | |
| Modificada | Alta (7.5) | 0.62% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (4.3) | 1.2% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which… | |
| Modificada | Media (6.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.3) | 0.56% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 3/5/2023 | 17/6/2026 | When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelNetapp HCI Baseboard Management Controller | 1/5/2023 | 17/6/2026 | A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past… | |
| Modificada | Alta (7) | 0.36% | — | Linux KernelNetapp HCI Baseboard Management Controller | 24/4/2023 | 17/6/2026 | A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel. | |
| Modificada | Alta (8.8) | 0.47% | — | Linuxfoundation Kubewarden-controller | 19/4/2023 | 17/6/2026 | An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount kubewarden-controller This issue affects: SUSE kubewarden kubewarden-controller versions prior to 1.6.0. |