Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Media (5.5) | 0.22% | — | Fortinet ForticlientFortinet Forticonverter | 13/6/2023 | 17/6/2026 | An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper with files in the installation folder, if… | |
| Modificada | Alta (7.8) | 0.20% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.5) | 13% | — | Rozcom Client | 30/5/2023 | 17/6/2026 | ROZCOM server framework - Misconfiguration may allow information disclosure via an unspecified request. | |
| Modificada | Alta (7.8) | 2.1% | — | Rozcom Client | 30/5/2023 | 17/6/2026 | ROZCOM client CWE-798: Use of Hard-coded Credentials | |
| Modificada | Media (6.1) | 0.44% | — | SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI | 9/5/2023 | 17/6/2026 | SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS)… | |
| Modificada | Media (5.4) | 0.37% | — | SAP Customer Relationship Management Webclient UISAP S4fndSapscore | 9/5/2023 | 17/6/2026 | SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After… | |
| Modificada | Alta (7.5) | 2.2% | — | Microsoft Typed-rest-client | 26/4/2023 | 17/6/2026 | typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send any request with… | |
| Modificada | Media (4.8) | 0.37% | — | Electric Studio Client Login Project Electric Studio Client Login | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in James Irving-Swift Electric Studio Client Login plugin <= 0.8.1 versions. | |
| Analizada | Media (6.5) | 2.1% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+10 | 11/4/2023 | 17/6/2026 | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 0.12% | — | Fortinet Forticlient | 11/4/2023 | 17/6/2026 | A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all versions, 5.0 all versions and 4.0 all versions may allow a local attacker to escalate their privileges via… | |
| Modificada | Alta (8.1) | 0.70% | — | Fortinet Forticlient | 11/4/2023 | 17/6/2026 | Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on the same file sharing network to execute commands via… | |
| Modificada | Alta (7.8) | 0.35% | — | Fortinet Forticlient | 11/4/2023 | 17/6/2026 | A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe. | |
| Modificada | Alta (7.8) | 0.17% | — | Fortinet Forticlient | 11/4/2023 | 17/6/2026 | A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe. | |
| Modificada | Media (5.4) | 0.44% | — | SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI | 11/4/2023 | 17/6/2026 | SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form… | |
| Modificada | Media (4.4) | 0.29% | — | Cynet Client Agent | 28/3/2023 | 17/6/2026 | Cynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling process privilege tokens. | |
| Modificada | Alta (8.8) | 0.26% | — | Cozmoslabs Client Portal | 15/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin <= 1.1.8 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Client Logo Carousel Project Client Logo Carousel | 13/3/2023 | 17/6/2026 | The Client Logo Carousel WordPress plugin through 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.34% | — | SAP Customer Relationship Management Webclient UISAP S4fnd | 14/2/2023 | 17/6/2026 | SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application. | |
| Analizada | Media (4.4) | 0.52% | — | Owncloud Client | 13/2/2023 | 17/6/2026 | La aplicación ownCloud para Android permite a los usuarios de ownCloud acceder, compartir y editar archivos y carpetas. Antes de la versión 3.0, la aplicación tenía una solución incompleta para un problema de Path Traversal y era vulnerable a dos métodos de omisión. Las omisiones pueden dar lugar a la divulgación de… | |
| Modificada | Media (5.5) | 0.46% | — | Owncloud Client | 13/2/2023 | 17/6/2026 | La aplicación ownCloud para Android permite a los usuarios de ownCloud acceder, compartir y editar archivos y carpetas. La versión 2.21.1 de la aplicación ownCloud para Android es vulnerable a la inyección SQL en `FileContentProvider.kt`. Este problema puede dar lugar a la divulgación de información. Dos bases de… |