Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | ARM Development StudioARM DS Development Studio | 27/7/2023 | 17/6/2026 | An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files. | |
| Modificada | Alta (7.8) | 0.17% | — | ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+2 | 27/7/2023 | 17/6/2026 | When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code. | |
| Modificada | Alta (7.8) | 0.18% | — | ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+7 | 27/7/2023 | 17/6/2026 | When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code. | |
| Modificada | Media (6.5) | 0.45% | — | Microfocus Cobol ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Test Server+1 | 20/7/2023 | 17/6/2026 | A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this… | |
| Modificada | Media (5.3) | 0.59% | — | Wpdeveloper Essential Addons FOR Elementor | 20/7/2023 | 17/6/2026 | The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 5.8.1 due to the plugin adding the API key to the source code of any page running the MailChimp block. This makes it possible for unauthenticated attackers to obtain a site's… | |
| Modificada | Baja (3.3) | 0.20% | — | Zoom Software Development KIT | 11/7/2023 | 17/6/2026 | Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable information disclosure via local access. | |
| Modificada | Media (4.3) | 0.38% | — | Wpdeveloper Notificationx | 1/7/2023 | 17/6/2026 | The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the generate_conversions() function. This makes it possible for unauthenticated attackers to generate conversions via a forged request… | |
| Modificada | Media (4.3) | 0.38% | — | Wpexpertdeveloper WP Private Content Plus | 1/7/2023 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_groups() function. This makes it possible for unauthenticated attackers to add new group members via a forged request… | |
| Modificada | Alta (7.5) | 0.53% | — | Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom+5 | 30/6/2023 | 17/6/2026 | La exposición de información destinada a ser cifrada por algunos clientes Zoom puede dar lugar a la divulgación de información sensible. | |
| Modificada | Alta (7.5) | 0.54% | — | Wpdeveloper Embedpress | 27/6/2023 | 17/6/2026 | El plugin User Registration para WordPress es vulnerable a la exposición de información confidencial debido a la clave de cifrado embebida en las funciones "lock_content_form_handler" y "display_password_form" en versiones hasta la 3.7.3 inclusive. Esto hace posible que atacantes no autenticados descifren y vean el… | |
| Modificada | Alta (8.8) | 0.90% | — | Amazon AWS Cloud Development KIT | 23/6/2023 | 17/6/2026 | AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. In the packages `aws-cdk-lib` 2.0.0 until 2.80.0 and `@aws-cdk/aws-eks` 1.57.0 until 1.202.0, `eks.Cluster` and `eks.FargateCluster` constructs create… | |
| Modificada | Alta (8.8) | 0.42% | — | Silabs Unify Software Development KIT | 21/6/2023 | 17/6/2026 | Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution. | |
| Modificada | Media (5.5) | 0.16% | — | Silabs Gecko Software Development KIT | 15/6/2023 | 17/6/2026 | The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized. | |
| Modificada | Media (6.5) | 0.29% | — | Silabs Bluetooth LOW Energy Software Development KIT | 15/6/2023 | 17/6/2026 | A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error. | |
| Modificada | Crítica (9.8) | 0.76% | — | Silabs Gecko Software Development KIT | 15/6/2023 | 17/6/2026 | Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack. | |
| Modificada | Media (4.3) | 0.32% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can… | |
| Modificada | Media (4.3) | 0.57% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is… | |
| Modificada | Media (4.3) | 0.61% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present,… | |
| Modificada | Media (4.3) | 0.51% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin settings. While a nonce check is present, it is only… | |
| Modificada | Media (4.3) | 0.57% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only executed… | |
| Modificada | Media (6.5) | 0.94% | — | Redhat Openshift API FOR Data ProtectionRedhat Openshift Container PlatformRedhat Openshift Developer Tools AND Services | 6/6/2023 | 17/6/2026 | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array,… | |
| Modificada | Alta (8.8) | 17% | 💥 PoC | Wpdeveloper Reviewx | 6/6/2023 | 17/6/2026 | The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by… | |
| Modificada | Baja (3.3) | 0.25% | — | Silabs Gecko Software Development KIT | 2/6/2023 | 17/6/2026 | Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap. | |
| Modificada | Media (6.5) | 0.75% | — | Nfine Rapid Development Platform | 25/5/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an unknown part of the file /SystemManage/Role/GetGridJson?keyword=&page=1&rows=20. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Media (6.5) | 0.68% | — | Nfine Rapid Development Platform Project Nfine Rapid Development Platform | 25/5/2023 | 17/6/2026 | A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /SystemManage/Organize/GetTreeGridJson?_search=false&nd=1681813520783&rows=10000&page=1&sidx=&sord=asc. The manipulation leads to improper access… |