Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

227 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.52%—Govee LED Strip Firmware30/10/202317/6/2026
An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.
ModificadaMedia (4.8)0.32%—IBM Security Verify Governance23/10/202317/6/2026
IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256037.
ModificadaAlta (8.8)1.1%—IBM Security Verify Governance23/10/202317/6/2026
IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 256036.
ModificadaAlta (7.5)0.26%—IBM Security Verify Governance23/10/202317/6/2026
IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.
ModificadaCrítica (9.8)0.59%—IBM Security Verify Governance23/10/202317/6/2026
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 225222.
ModificadaAlta (7.8)0.68%—Justsystems Easy Postcard MAXJustsystems Ichitaro 2021Justsystems Ichitaro 2022Justsystems Ichitaro 2023+1519/10/202317/6/2026
An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause a type confusion, which can lead to memory corruption and eventually arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.8)0.65%—Justsystems Easy Postcard MAXJustsystems Ichitaro 2021Justsystems Ichitaro 2022Justsystems Ichitaro 2023+1519/10/202317/6/2026
An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to…
ModificadaAlta (7.8)0.64%—Justsystems Easy Postcard MAXJustsystems Ichitaro 2021Justsystems Ichitaro 2022Justsystems Ichitaro 2023+1519/10/202317/6/2026
A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause memory corruption, resulting in arbitrary code execution. Victim would need to open a malicious file to trigger this vulnerability.
ModificadaAlta (7.8)0.48%—Justsystems Easy Postcard MAXJustsystems Ichitaro 2021Justsystems Ichitaro 2022Justsystems Ichitaro 2023+1519/10/202317/6/2026
An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of Ichitaro 2023 1.0.1.59372 when processing types 0x0000-0x0009 of a style record with the type 0x2008. A specially crafted document can cause memory corruption, which can lead to…
ModificadaCrítica (9.8)0.44%—IBM Security Verify Governance16/10/202317/6/2026
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 256016.
ModificadaAlta (7.2)0.37%—IBM Security Verify Governance16/10/202317/6/2026
IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.
ModificadaMedia (4.4)0.17%—IBM Security Verify Governance16/10/202317/6/2026
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
ModificadaMedia (4.3)0.36%—E-gov11/10/202317/6/2026
e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a…
ModificadaAlta (7.5)0.78%—Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+510/10/202317/6/2026
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a…
ModificadaAlta (8.8)0.51%—Govee Home11/9/202317/6/2026
Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.
ModificadaAlta (7.8)0.19%—Fabasoft CloudFabasoft Cloud Enterprise ClientFabasoft Folio / Egov-suite3/8/202317/6/2026
Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.
ModificadaAlta (8.8)1.3%—IBM Security Verify Governance31/7/202317/6/2026
IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 257873.
ModificadaMedia (6.5)1.2%—IBM Security Verify Governance31/7/202317/6/2026
IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257772.
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
ModificadaMedia (6.1)0.51%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
ModificadaMedia (5.4)0.56%—Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager26/1/202317/6/2026
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
ModificadaAlta (7.5)0.48%—IBM Security Verify Governance26/1/202317/6/2026
IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225078.
ModificadaMedia (5.5)0.12%—IBM Security Verify Governance9/1/202317/6/2026
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232.
ModificadaMedia (5.3)0.72%—IBM Security Verify Governance24/12/202217/6/2026
IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 224915.
ModificadaMedia (6.5)0.79%—IBM Security Verify Governance22/12/202217/6/2026
IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009.
Orbitaley — Vulnerabilidades