Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

2615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.73%—Open-xchange Appsuite Frontend2/8/202317/6/2026
The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary…
ModificadaMedia (5.4)0.66%—Open-xchange Appsuite Frontend2/8/202317/6/2026
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would…
ModificadaMedia (5.4)0.66%—Open-xchange Appsuite Frontend2/8/202317/6/2026
The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the…
ModificadaMedia (5.4)0.66%—Open-xchange Appsuite Frontend2/8/202317/6/2026
The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary…
ModificadaMedia (5.4)0.66%—Open-xchange Appsuite Frontend2/8/202317/6/2026
Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this…
ModificadaCrítica (9.8)0.82%—Open-xchange Appsuite Backend2/8/202317/6/2026
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT…
ModificadaBaja (3.2)0.36%—Open-xchange Appsuite Office2/8/202317/6/2026
In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricted network with the capability to intercept and replay HTTP requests to sproxyd (or who is in control of the sproxyd service) could perform a…
ModificadaMedia (5.5)0.40%—Open-xchange Appsuite Office2/8/202317/6/2026
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are accessible by the services system user…
ModificadaAlta (7.8)0.41%—Open-xchange Appsuite Office2/8/202317/6/2026
Se podía abusar de la API de Cache Service para inyectar indirectamente parámetros con sintaxis SQL que no estaban suficientemente sanitizados y que posteriormente se ejecutaban al crear nuevos grupos de caché. Los atacantes con acceso a una red local o restringida podían realizar consultas SQL arbitrarias. Se ha…
ModificadaAlta (7.8)0.43%—Open-xchange Appsuite Office2/8/202317/6/2026
Se podía abusar de la API de Cache Service para inyectar parámetros con sintaxis SQL que no estaba suficientemente sanitizada antes de ejecutarse como sentencia SQL. Los atacantes con acceso a una red local o restringida podían realizar consultas SQL arbitrarias, descubriendo los datos almacenados en caché de otros…
ModificadaBaja (3.1)0.60%—Open-xchange Appsuite Backend2/8/202317/6/2026
Las búsquedas de servicios externos para una serie de protocolos eran vulnerables a una debilidad de condición de carrera de tiempo de comprobación/tiempo de uso (TOCTOU), que afectaba a JDK DNS Cache. Los atacantes que sincronizaban correctamente la expiración de la caché DNS podían inyectar una configuración que…
ModificadaMedia (4.3)0.75%—Open-xchange Appsuite Backend2/8/202317/6/2026
Los atacantes con acceso a cuentas de usuario pueden inyectar caracteres de control arbitrarios a las reglas del filtro de correo SIEVE. Esto podría ser abusado para acceder a extensiones de SIEVE que no están permitidas por App Suite o para inyectar reglas que romperían el procesamiento de filtros por usuario,…
AnalizadaMedia (6.1)49%⚠ Explotación activa💥 ExploitSynacor Zimbra Collaboration Suite31/7/202317/6/2026
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
ModificadaMedia (6.1)0.53%—Mobisystems Office Suite20/7/202317/6/2026
Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the filter parameter at /api?path=files.
ModificadaAlta (7.5)1.2%—Mobisystems Office Suite20/7/202317/6/2026
Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts.
ModificadaMedia (6.1)0.53%—Mobisystems Office Suite20/7/202317/6/2026
Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /api?path=profile.
ModificadaMedia (4.4)0.13%—Dell Wyse Management Suite20/7/202317/6/2026
Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerability. An authenticated malicious user having local access to the system running the application could exploit this vulnerability to read sensitive information written to log files.
ModificadaMedia (4.9)0.45%—Dell Wyse Management Suite20/7/202317/6/2026
Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious user with privileged access can push policies to unauthorized tenant group.
ModificadaMedia (6.5)0.60%—Dell Wyse Management Suite20/7/202317/6/2026
Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood the configured SMTP server with numerous requests in order to deny access to the system.
ModificadaMedia (6.1)0.42%—Oracle E-business Suite18/7/202317/6/2026
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human…
ModificadaMedia (4.3)0.46%—Oracle E-business Suite18/7/202317/6/2026
Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: Reports Configuration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology.…
ModificadaAlta (8.8)0.35%—Salesagility Suitecrm11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
ModificadaAlta (8.8)0.26%—Hasthemes Wishsuite11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3 versions.
ModificadaAlta (7.5)0.61%—Deltaww Infrasuite Device Master10/7/202317/6/2026
​An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.
ModificadaCrítica (9.8)2.0%💥 PoCDeltaww Infrasuite Device Master10/7/202317/6/2026
​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.
Orbitaley — Vulnerabilidades