Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 1.00% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.3) | 1.00% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 1.00% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 0.60% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.20% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (8.8) | 0.80% | — | Thedaylightstudio Fuel CMS | 9/6/2023 | 17/6/2026 | Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php. | |
| Modificada | Alta (8) | 0.24% | — | PTC Vuforia Studio | 7/6/2023 | 17/6/2026 | PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a replay attack. | |
| Modificada | Media (4.3) | 0.50% | — | PTC Vuforia Studio | 7/6/2023 | 17/6/2026 | Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path. | |
| Modificada | Alta (7.5) | 0.47% | — | PTC Vuforia Studio | 7/6/2023 | 17/6/2026 | The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication. | |
| Modificada | Alta (8.1) | 0.45% | — | PTC Vuforia Studio | 7/6/2023 | 17/6/2026 | By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account. | |
| Modificada | Crítica (9.9) | 0.66% | — | PTC Vuforia Studio | 7/6/2023 | 17/6/2026 | A user could use the “Upload Resource” functionality to upload files to any location on the disk. | |
| Modificada | Baja (3.3) | 0.13% | — | PTC Vuforia Studio | 7/6/2023 | 17/6/2026 | An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid. | |
| Modificada | Crítica (9.8) | 1.2% | — | Timmystudios Keyboard Themes | 1/6/2023 | 17/6/2026 | Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution. | |
| Modificada | Alta (8.8) | 1.4% | — | Beekeeperstudio Beekeeper-studio | 23/5/2023 | 17/6/2026 | Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of the application on the PC where the affected product is installed. As a result, an arbitrary OS command may be executed as well. | |
| Modificada | Alta (8.8) | 0.32% | — | Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware | 22/5/2023 | 17/6/2026 | The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files. | |
| Modificada | Crítica (9.8) | 0.46% | — | Birddog A300 FirmwareBirddog Mini FirmwareBirddog 4K Quad FirmwareBirddog Studio R3 Firmware | 22/5/2023 | 17/6/2026 | Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials. | |
| Modificada | Alta (8.8) | 0.25% | — | Studiowombat Shoppable Images | 18/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Studio Wombat Shoppable Images plugin <= 1.2.3 versions. |