Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.57% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.65% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.66% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message | |
| Modificada | Alta (7.5) | 0.65% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.60% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server may experience a DoS due to a stack overflow when handling a specially crafted message. | |
| Modificada | Media (5.9) | 0.46% | — | Jenkins Active Directory | 12/7/2023 | 17/6/2026 | Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory… | |
| Modificada | Alta (7.2) | 1.1% | — | Vsourz ALL IN ONE Redirection | 10/7/2023 | 17/6/2026 | The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Alta (8.8) | 0.31% | — | Wpplugin Contact Form 7 Redirect & Thank YOU Page | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions. | |
| Modificada | Alta (8.8) | 1.6% | 💥 Exploit | Ozette Simple Mobile URL Redirect | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions. | |
| Modificada | Alta (8.8) | 0.32% | — | Premmerce Redirect Manager | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions. | |
| Modificada | Media (4.3) | 0.39% | — | Goldplugins Staff Directory Plugin | 1/7/2023 | 17/6/2026 | The Staff Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request… | |
| Modificada | Alta (7.5) | 0.53% | — | Miniorange Active Directory Integration / Ldap Integration | 29/6/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to… | |
| Modificada | Media (5.4) | 0.37% | — | Connections-pro Connections Business Directory | 26/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin <= 10.4.36 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Add-to-cart-direct-checkout-for-woocommerce | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, Quick purchase button, Buy now button, Quick View button for WooCommerce plugin <= 2.1.48 versions. | |
| Modificada | Crítica (9.8) | 0.51% | — | Ipandlanguageredirect Project Ipandlanguageredirect | 16/6/2023 | 17/6/2026 | The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection. | |
| Modificada | Alta (7.2) | 0.79% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 podría permitir a un usuario con privilegios cargar archivos maliciosos con formatos peligrosos que pueden procesarse automáticamente en el entorno del producto. ID de IBM X-Force: 228586. | |
| Modificada | Alta (7.5) | 0.85% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 utiliza una configuración de bloqueo de cuentas inadecuada que podría permitir a un atacante remoto forzar las credenciales de las cuentas. ID de IBM X-Force: 228510. | |
| Modificada | Alta (8.8) | 1.4% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios en el sistema enviando una solicitud especialmente manipulada. ID de IBM X-Force: 228439. | |
| Modificada | Alta (7.5) | 0.77% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 podría permitir a un atacante provocar una denegación de servicio debido al consumo incontrolado de recursos. ID de IBM X-Force: 228588. | |
| Modificada | Alta (8.1) | 0.50% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 especifica permisos para un recurso crítico para la seguridad de una forma que permite que dicho recurso sea leído o modificado por actores no deseados. ID de IBM X-Force: 228571. | |
| Modificada | Media (6.5) | 0.34% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 almacena las credenciales de usuario en texto sin formato que puede leer un usuario autenticado. ID de IBM X-Force: 228567. | |
| Modificada | Media (4.8) | 0.62% | 💥 Exploit | Redirect After Login Project Redirect After Login | 13/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 versions. | |
| Modificada | Media (4.3) | 0.64% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to delete… | |
| Modificada | Crítica (9.8) | 1.7% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be… | |
| Modificada | Media (4.7) | 0.34% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the 'insert' function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious… |