Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 18 respecto a la semana anterior
Críticas / altas1271▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
2095 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+26 | 2/8/2023 | 17/6/2026 | Las plataformas F5 BIG-IP específicas con tarjetas Cavium Nitrox FIPS HSM generan una contraseña determinista para la cuenta Crypto User. La naturaleza predecible de la contraseña permite a un usuario autenticado con acceso TMSH al sistema BIG-IP, o a cualquiera con acceso físico al FIPS HSM, la información necesaria… | |
| Modificada | Media (5.4) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 2/8/2023 | 17/6/2026 | Existe una vulnerabilidad de Cross-Site Scripting (XSS) en una página no revelada de la utilidad de configuración de BIG-IP que permite a un atacante ejecutar JavaScript en el contexto del usuario actualmente conectado. Nota: No se evalúan las versiones de software que han alcanzado el fin de soporte técnico (EoTS). | |
| Modificada | Media (4.3) | 0.55% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 2/8/2023 | 17/6/2026 | Un atacante autenticado con privilegios de invitado o superior puede provocar la finalización del proceso iControl SOAP mediante el envío de solicitudes no reveladas. Nota: No se evalúan las versiones de software que han alcanzado el fin del soporte técnico (EoTS). | |
| Modificada | Media (6.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 2/8/2023 | 17/6/2026 | Existe una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en una página no revelada de la utilidad de configuración de BIG-IP que permite a un atacante ejecutar JavaScript en el contexto del usuario actualmente conectado. Nota: No se evalúan las versiones de software que han alcanzado el fin del soporte ténico… | |
| Modificada | Media (6.5) | 0.32% | — | Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+6 | 31/7/2023 | 17/6/2026 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts… | |
| Modificada | Media (6.5) | 0.82% | — | IBM B2B Advanced CommunicationsIBM Multi-enterprise Integration Gateway | 31/7/2023 | 17/6/2026 | IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 could allow a user to cause a denial of service due to the deserializing of untrusted serialized Java objects. IBM X-Force ID: 246976. | |
| Modificada | Media (5.4) | 0.35% | — | IBM B2B Advanced CommunicationsIBM Multi-enterprise Integration Gateway | 31/7/2023 | 17/6/2026 | IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Modificada | Alta (7.5) | 0.67% | — | Advancedplugins Ultimateimagetool | 20/7/2023 | 17/6/2026 | In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack. | |
| Modificada | Alta (7.1) | 0.30% | — | Advancemame | 18/7/2023 | 17/6/2026 | Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1. | |
| Modificada | Media (4.3) | 0.39% | — | Ashstonestudios Advanced Popups | 12/7/2023 | 17/6/2026 | The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the metabox_popup_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted… | |
| Modificada | Alta (8.8) | 0.25% | — | Piwebsolution Advanced-free-flat-shipping-woocommerce | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1.6.4.4 versions. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Advancedfilemanager File Manager Advanced Shortcode | 27/6/2023 | 17/6/2026 | The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users. | |
| Modificada | Alta (7.8) | 0.25% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 23/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Media (4.8) | 0.37% | — | Advanced Text Widget Project Advanced Text Widget | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Chirkov Advanced Text Widget plugin <= 2.1.2 versions. | |
| Modificada | Crítica (9.8) | 0.69% | — | Online Shopping System Advanced Project Online Shopping System Advanced | 20/6/2023 | 17/6/2026 | A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper authentication. The attack can be launched… | |
| Modificada | Media (5.4) | 0.59% | — | Online-shopping-system-advanced Project Online-shopping-system-advanced | 18/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Media (4.4) | 0.54% | — | Advanced-woo-search Advanced WOO Search | 9/6/2023 | 17/6/2026 | The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (6.5) | 0.65% | — | Zorem Advanced Shipment Tracking FOR Woocommerce | 7/6/2023 | 17/6/2026 | The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5… | |
| Modificada | Baja (3.3) | 0.19% | — | Advancemame Advancecomp | 6/6/2023 | 17/6/2026 | A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased availability. | |
| Modificada | Alta (7.8) | 0.20% | — | Redhat Advanced Cluster Management FOR Kubernetes | 5/6/2023 | 17/6/2026 | The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster) of taking advantage of cluster scoped access in a created policy. This feature does not restrict… | |
| Modificada | Alta (8.1) | 0.47% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability. | |
| Modificada | Media (5.4) | 0.34% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability. | |
| Modificada | Alta (7.8) | 0.19% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability. |