Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
386 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Atlassian Confluence Data CenterAtlassian Confluence Server | 4/10/2023 | 17/6/2026 | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.… | |
| Modificada | Alta (8.8) | 15% | — | Atlassian Bitbucket Data CenterAtlassian Bitbucket Server | 19/9/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Alta (8.8) | 0.73% | — | Esds.co Emagic Data Center Management | 8/8/2023 | 17/6/2026 | This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system. | |
| Modificada | Alta (8.8) | 34% | 💥 Exploit | Esds.co Emagic Data Center Management | 8/8/2023 | 17/6/2026 | This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary… | |
| Modificada | Alta (8.8) | 2.1% | — | Atlassian Bamboo Data CenterAtlassian Bamboo Server | 19/7/2023 | 17/6/2026 | This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center. This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call… | |
| Modificada | Alta (8.8) | 2.2% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 18/7/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to… | |
| Modificada | Alta (8.8) | 2.1% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 18/7/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to… | |
| Modificada | Alta (7.2) | 0.86% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored. | |
| Modificada | Alta (7.2) | 0.86% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages. | |
| Modificada | Alta (8.8) | 0.60% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration… | |
| Modificada | Alta (8.8) | 0.60% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of… | |
| Modificada | Media (6.1) | 0.47% | — | Broadcom Vmware Nsx-t Data Center | 26/5/2023 | 17/6/2026 | NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.55% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Uncontrolled search path in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.59% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Protection mechanism failure in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (6.5) | 0.53% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable information disclosure via network access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 0.79% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 1/5/2023 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder… | |
| Modificada | Alta (8.1) | 0.82% | — | Schneider-electric Struxureware Data Center Expert | 18/4/2023 | 17/6/2026 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) | |
| Modificada | Alta (7.8) | 0.59% | — | Schneider-electric Struxureware Data Center Expert | 18/4/2023 | 17/6/2026 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected products: StruxureWare Data Center Expert (V7.9.2… | |
| Modificada | Media (6.1) | 0.39% | — | Schneider-electric Struxureware Data Center Expert | 18/4/2023 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) | |
| Modificada | Alta (8.1) | 0.50% | — | Schneider-electric Struxureware Data Center Expert | 18/4/2023 | 17/6/2026 | A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) |