Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.64% | — | GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. | |
| Modificada | Media (5.5) | 0.61% | — | GNU BinutilsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. | |
| Modificada | Media (6.1) | 0.38% | — | Churchadminplugin Church Admin | 16/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions. | |
| Modificada | Crítica (9.8) | 0.95% | — | Wolf18 Easyadmin8 | 15/8/2023 | 17/6/2026 | La vulnerabilidad de carga de archivos en EasyAdmin8 v.1.0 de Wolf-leo permite a un atacante remoto ejecutar código arbitrario a través de la función de tipo de carga. | |
| Modificada | Media (6.1) | 0.35% | — | Genesys Administrator Extension | 13/8/2023 | 17/6/2026 | Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261. | |
| Modificada | Alta (8.8) | 0.80% | — | Pearadmin Pear Admin Think | 11/8/2023 | 17/6/2026 | SQL Injection en pear-admin-think versión 2.1.2, permite a los atacantes ejecutar código arbitrario y escalar privilegios a través de una petición GET a Crud.php. | |
| Modificada | Crítica (9.8) | 0.63% | — | Farmakom Remote Administration Console | 8/8/2023 | 17/6/2026 | Neutralización inadecuada de elementos especiales utilizados en un comando SQL ('SQL Injection') vulnerabilidad en la Consola de Administración Remota Farmakom permite SQL Injection. Este problema afecta a la Consola de Administración Remota: antes de 1.02. | |
| Modificada | Crítica (9.8) | 3.5% | 💥 Exploit | Wifi-soft Unibox Administration | 31/7/2023 | 17/6/2026 | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page. | |
| Analizada | Crítica (9.8) | 0.57% | — | CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+4 | 25/7/2023 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of… | |
| Modificada | Media (6.6) | 0.64% | — | Wolfcode Easyadmin8 | 20/7/2023 | 17/6/2026 | A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function of the file /admin/index/index.html#/admin/mall.goods/index.html of the component File Upload Module. The manipulation leads to unrestricted upload. The complexity of an attack is rather high. The… | |
| Modificada | Media (6) | 0.21% | — | Oracle Hyperion Essbase Administration Services | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion… | |
| Modificada | Alta (8.8) | 0.26% | — | Wpadmin AWS CDN | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPAdmin WPAdmin AWS CDN plugin <= 2.0.13 versions. | |
| Modificada | Alta (7.5) | 2.0% | — | ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+2 | 17/7/2023 | 17/6/2026 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | |
| Modificada | Media (5.3) | 0.62% | — | OpensslManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration Utility | 14/7/2023 | 17/6/2026 | Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding… | |
| Modificada | Alta (7.5) | 0.97% | — | Codecentric Spring Boot AdminThymeleaf | 14/7/2023 | 17/6/2026 | Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to… | |
| Modificada | Media (6.1) | 0.58% | — | Pimcore Admin Classic Bundle | 11/7/2023 | 17/6/2026 | Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of privilege, causing the application to execute arbitrary scripts/HTML content. This vulnerability has been… | |
| Modificada | Media (6.8) | 1.9% | — | Microsoft Windows Admin Center | 11/7/2023 | 17/6/2026 | Windows Admin Center Spoofing Vulnerability | |
| Modificada | Media (5.4) | 0.51% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 6/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field. | |
| Modificada | Media (6.1) | 0.73% | 💥 Exploit | Wp-experts Protect WP Admin | 4/7/2023 | 17/6/2026 | The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered. | |
| Modificada | Media (6.1) | 0.41% | — | User Registration & Login AND User Management System With Admin Panel Project User Registration & Login AND User Management System With Admin Panel | 29/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php. | |
| Modificada | Alta (7.5) | 0.50% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Alta (7.2) | 1.3% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. | |
| Modificada | Alta (8.1) | 0.55% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. |