Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.99% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | La validación incorrecta del parámetro de contraseña en Time Slots Booking Calendar v 3.3 de PHPJabbers resulta en contraseñas inseguras. | |
| Modificada | Media (6.1) | 0.50% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | Existe una vulnerabilidad de Cross Site Scripting (XSS) en el parámetro "cid" de preview.php en Time Slots Booking Calendar v3.3 de PHPJabbers. | |
| Modificada | Media (5.4) | 0.49% | — | Fsmlabs Timekeeper | 26/7/2023 | 17/6/2026 | An XSS issue was discovered in FSMLabs TimeKeeper 8.0.17. On the "Configuration -> Compliance -> Add a new compliance report" and "Configuration -> Timekeeper Configuration -> Add a new source there" screens, there are entry points to inject JavaScript code. | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Fsmlabs Timekeeper | 26/7/2023 | 17/6/2026 | An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to… | |
| Modificada | Media (5.9) | 0.54% | — | Br-automation Automation Runtime | 26/7/2023 | 17/6/2026 | Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions. | |
| Modificada | Media (4.4) | 0.45% | — | Redhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFVFedoraproject Fedora+2 | 25/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service. | |
| Modificada | Media (6.7) | 0.46% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV | 24/7/2023 | 17/6/2026 | Se encontró una vulnerabilidad de double free en el manejo de objetos vmw_buffer_object en el controlador vmwgfx en el kernel de Linux. Este problema se produce debido a la falta de validación de la existencia de un objeto antes de realizar más operaciones libres en el objeto, lo que puede permitir a un usuario… | |
| Modificada | Media (5.3) | 0.34% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV | 24/7/2023 | 17/6/2026 | Se encontró una vulnerabilidad de condición de ejecución en el controlador vmwgfx del kernel de Linux. El fallo existe en el manejo de objetos GEM. El problema se debe a un bloqueo inadecuado al realizar operaciones en un objeto. Este fallo permite que un usuario local privilegiado revele información en el contexto… | |
| Modificada | Alta (8.8) | 0.26% | — | Nootheme NOO Timetable | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Gzscripts Time Slot Booking Calendar PHP | 7/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be initiated… | |
| Modificada | Alta (8.1) | 1.2% | — | Uptime-kuma Project Uptime-kuma | 5/7/2023 | 17/6/2026 | Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma allows authenticated users to install plugins from an official list of plugins. This feature is currently disabled in the web interface, but the corresponding API endpoints are still available after… | |
| Modificada | Alta (8.8) | 2.0% | — | Uptime-kuma Project Uptime-kuma | 5/7/2023 | 17/6/2026 | Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in versions prior to 1.22.1, which may lead to remote code execution. Uptime Kuma allows authenticated users to install plugins from an official list of plugins. This feature is currently disabled in… | |
| Modificada | Media (4.3) | 0.48% | — | Coolplugins Cool Timeline | 1/7/2023 | 17/6/2026 | The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the ctl_save() function. This makes it possible for unauthenticated attackers to save field icons via a… | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Pi-woocommerce-order-date-time-and-type | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date time, Pickup Location, delivery date for WooCommerce plugin <= 3.0.19 versions. | |
| Modificada | Media (5.4) | 0.34% | — | Techtime User Management | 26/6/2023 | 17/6/2026 | The TechTime User Management components for Atlassian products allow stored XSS on the Bulk User Actions page. This affects User Management for Jira 2.0.0 through 2.17.1, User Management for Confluence 2.0.0 through 2.15.24, and User Management for Bitbucket 2.2.2 through 2.15.24. | |
| Modificada | Media (5.4) | 0.40% | — | Mmrs151 Daily Prayer Time | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 versions. | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | Ossrs Simple Realtime Server | 12/6/2023 | 17/6/2026 | SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vulnerable to a drive-by command injection. An attacker may send a request to the `/api/v1/snapshots` endpoint containing any commands to be… | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Alta (8.1) | 0.59% | — | Mobatime Amxgt 100 | 5/6/2023 | 17/6/2026 | Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including administratorsThis issue affects Mobatime mobile application AMXGT100: through 1.3.20. | |
| Modificada | Crítica (9.1) | 0.78% | — | Mobatime Amxgt 100 | 5/6/2023 | 17/6/2026 | Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile application AMXGT100 through 1.3.20. | |
| Modificada | Media (5.3) | 0.60% | — | Mobatime Amxgt 100 | 5/6/2023 | 17/6/2026 | Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2023-3065 and 3066)This issue affects Mobatime mobile application AMXGT100 through 1.3.20. | |
| Modificada | Alta (8.8) | 0.60% | — | Mobatime WEB Application | 2/6/2023 | 17/6/2026 | Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobatime web application: through 06.7.22. | |
| Modificada | Alta (8.8) | 0.82% | — | Mobatime WEB Application | 2/6/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user to Upload a Web Shell to a Web Server.This issue affects Mobatime web application: through 06.7.22. | |
| Modificada | Crítica (9.8) | 0.63% | — | DenoDeno Runtime | 31/5/2023 | 17/6/2026 | Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies relying on these built-in modules are subject… | |
| Modificada | Media (5.4) | 0.39% | — | Leantime | 30/5/2023 | 17/6/2026 | Leantime is a lean open source project management system. Starting in version 2.3.21, an authenticated user with commenting privileges can inject malicious Javascript into a comment. Once the malicious comment is loaded in the browser by a user, the malicious Javascript code executes. As of time of publication, a… |