Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.81% | — | Erofs-utils Project Erofs-utils | 1/6/2023 | 17/6/2026 | Desbordamiento de Búfer en la función erofsfsck_dirent_iter en fsck/main.c en erofs-utils v1.6 permite a atacantes remotos ejecutar código arbitrario a través de una imagen del sistema de archivos erofs manipulada. | |
| Modificada | Alta (8.8) | 5.3% | 💥 Exploit | FS S3900 24t4s Firmware | 29/5/2023 | 17/6/2026 | FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password. | |
| Modificada | Alta (7.5) | 0.38% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+185 | 2/5/2023 | 17/6/2026 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | |
| Modificada | Crítica (9.8) | 2.4% | — | Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware | 14/4/2023 | 17/6/2026 | WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function. | |
| Modificada | Alta (8.8) | 17% | — | Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware | 14/4/2023 | 17/6/2026 | WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function. | |
| Modificada | Alta (7.8) | 0.08% | — | Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+215 | 13/4/2023 | 17/6/2026 | Memory corruption due to double free in core while initializing the encryption key. | |
| Modificada | Media (6.5) | 0.51% | — | Linuxfoundation Cubefs | 12/4/2023 | 17/6/2026 | CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation. This occurs because DaemonSet has cfs-csi-cluster-role and can thus list all secrets, including the admin secret. | |
| Modificada | Alta (7.5) | 3.5% | — | Oisf SuricataPfsensePfsense Suricata Package | 6/4/2023 | 17/6/2026 | Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php. | |
| Modificada | Alta (7.5) | 78% | — | Zohocorp Manageengine Adselfservice Plus | 5/4/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. | |
| Modificada | Crítica (9.6) | 0.67% | — | Netgate PfsenseNetgate Pfsense Acme Package | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php. | |
| Modificada | Media (6.5) | 0.60% | — | Dell EMC Powerscale Onefs | 4/4/2023 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell EMC Powerscale Onefs | 4/4/2023 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability breaks the compliance mode guarantee. | |
| Modificada | Alta (7.8) | 0.21% | — | Dell EMC Powerscale Onefs | 4/4/2023 | 17/6/2026 | Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local attacker could potentially exploit this vulnerability, leading to system takeover and it breaks the compliance mode guarantees. | |
| Modificada | Crítica (9.8) | 3.6% | — | Go-fastdfs Project Go-fastdfs | 2/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit… | |
| Modificada | Crítica (9.1) | 3.1% | — | Zohocorp Manageengine Adselfservice Plus | 23/3/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications. | |
| Modificada | Crítica (9.8) | 9.8% | 💥 Exploit | Netgate Pfsense PlusPfsense | 22/3/2023 | 17/6/2026 | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests. | |
| Modificada | Alta (8.8) | 90% | 💥 Exploit | Netgate Pfsense | 17/3/2023 | 17/6/2026 | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml. | |
| Modificada | Media (4.8) | 0.39% | — | Afsanalytics AFS Analytics | 15/3/2023 | 17/6/2026 | Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions. | |
| Modificada | Alta (8.8) | 0.41% | — | Qualcomm Apq8009 FirmwareQualcomm Apq8009w FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+205 | 10/3/2023 | 17/6/2026 | Memory corruption in modem due to buffer overflow while processing a PPP packet | |
| Modificada | Media (6.7) | 0.11% | — | Dell Powerscale Onefs | 2/3/2023 | 17/6/2026 | Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover. | |
| Modificada | Alta (7.1) | 0.15% | — | Dell EMC Powerscale Onefs | 28/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability to overwrite arbitrary files causing denial of service. | |
| Modificada | Media (6.1) | 60% | — | Netgate Pfsense | 22/2/2023 | 17/6/2026 | pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters. | |
| Modificada | Alta (7.5) | 0.91% | — | Glusterfs | 21/2/2023 | 17/6/2026 | In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read. | |
| Modificada | Alta (7.5) | 0.87% | — | Glusterfs | 21/2/2023 | 17/6/2026 | In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free. | |
| Modificada | Alta (7.5) | 0.58% | — | Netgear Prosafe Fs726tp Firmware | 15/2/2023 | 17/6/2026 | An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text. |