Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
2287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.37% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144. | |
| Modificada | Media (4.3) | 0.44% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134. | |
| Modificada | Media (6.5) | 0.63% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403. | |
| Modificada | Media (5.3) | 0.59% | — | Trianglemicroworks Scada Data Gateway | 7/6/2023 | 17/6/2026 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker… | |
| Modificada | Crítica (9.8) | 0.71% | — | Trianglemicroworks Scada Data Gateway | 7/6/2023 | 17/6/2026 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly… | |
| Modificada | Media (5.4) | 0.65% | — | Theme-fusion Avada | 7/6/2023 | 17/6/2026 | The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the update_layout function in versions up to, and including, 6.2.3 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers, and above, to inject arbitrary web scripts in pages that… | |
| Modificada | Crítica (9.8) | 0.71% | — | Advantech Webaccess/scada | 6/6/2023 | 17/6/2026 | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution. | |
| Modificada | Crítica (9.8) | 0.90% | — | Advantech Webaccess/scada | 6/6/2023 | 17/6/2026 | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution. | |
| Modificada | Alta (7.2) | 0.83% | — | Advantech Webaccess/scada | 6/6/2023 | 17/6/2026 | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.19% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre 3 07ach7 FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07ada05 Firmware+110 | 5/6/2023 | 17/6/2026 | An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.20% | — | IBM Qradar Wincollect | 31/5/2023 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0 through 10.1.3 could allow a local authenticated attacker to gain elevated privileges on the system. IBM X-Force ID: 248158. | |
| Modificada | Alta (7.8) | 0.19% | — | IBM Qradar Wincollect | 31/5/2023 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0 though 10.1.3 could allow a local user to execute commands on the system due to execution with unnecessary privileges. IBM X-Force ID: 248156. | |
| Modificada | Media (6.1) | 0.38% | — | Monitorclick Forms ADA | 29/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MonitorClick Forms Ada – Form Builder plugin <= 1.0 versions. | |
| Modificada | Alta (7.5) | 0.90% | — | Parseplatform Parse Server Push Adapter | 27/5/2023 | 17/6/2026 | parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can crash Parse Server due to an invalid push notification payload. This issue has been patched in version 4.1.3. | |
| Modificada | Alta (8.8) | 0.27% | — | Viadat Store Locator FOR Wordpress With Google Maps | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions. | |
| Modificada | Crítica (9.8) | 0.62% | — | Adampos Mobilmen EL Terminali Yazilimi | 23/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | SDG Pnpscada | 12/5/2023 | 17/6/2026 | The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively.… | |
| Modificada | Alta (7.5) | 0.44% | — | IBM Qradar Data Synchronization | 6/5/2023 | 17/6/2026 | IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370. | |
| Modificada | Alta (8.8) | 0.75% | — | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Alta (8.8) | 0.75% | — | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Alta (8.8) | 4.5% | — | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Alta (8.8) | 25% | — | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Alta (8.8) | 45% | 💥 Exploit | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Media (5.8) | 0.33% | — | Pingidentity PingfederatePingidentity Pingid Adapter FOR PingfederatePingidentity Pingid Integration KIT | 25/4/2023 | 17/6/2026 | A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA. | |
| Modificada | Alta (7.2) | 2.1% | 💥 PoC | Smartptt Scada | 14/4/2023 | 17/6/2026 | SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default). |