Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 0.68% | — | Shescape Project Shescape | 23/8/2023 | 17/6/2026 | shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell.… | |
| Modificada | Media (4.3) | 0.81% | — | Shescape Project Shescape | 23/6/2023 | 17/6/2026 | Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1. | |
| Modificada | Media (5.3) | 0.64% | — | Globalscape EFT Server | 22/6/2023 | 17/6/2026 | Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message | |
| Modificada | Alta (7.5) | 0.90% | — | Globalscape EFT Server | 22/6/2023 | 17/6/2026 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service | |
| Modificada | Crítica (9.1) | 0.97% | — | Globalscape EFT Server | 22/6/2023 | 17/6/2026 | Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23557. | |
| Modificada | Crítica (9.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23556. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command injection by authenticated users, aka OSFOURK-23554. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-24036. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e374b. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Media (6.1) | 0.32% | — | Canonical Landscape | 6/6/2023 | 17/6/2026 | Landscape allowed URLs which caused open redirection. | |
| Modificada | Alta (8.2) | 0.45% | — | Canonical Landscape | 6/6/2023 | 17/6/2026 | Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API. | |
| Modificada | Alta (7.5) | 0.55% | — | Canonical Landscape | 6/6/2023 | 17/6/2026 | Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e3c04. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.2) | 0.96% | — | Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller | 14/4/2023 | 17/6/2026 | Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands. | |
| Modificada | Alta (8.7) | 0.56% | — | SAP Landscape Management | 11/4/2023 | 17/6/2026 | An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain privileged access to other systems making those other systems vulnerable to information disclosure and modification.The disclosed information… |