Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
2087 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.56% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and… | |
| Modificada | Media (6.5) | 0.58% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Report Console contains various jobs that are executed on the server at specified intervals, e.g., backup, etc. An authenticated user has the ability to modify these entries… | |
| Modificada | Alta (7.5) | 0.49% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Arbitrary File Upload. The BaseController class, that each of the service controllers derives from, allows for the upload of arbitrary files. If the HTTP request is a multipart/form-data POST request, any parameters with a… | |
| Modificada | Crítica (9.8) | 0.82% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. The filename provided… | |
| Modificada | Baja (3.5) | 0.14% | — | BD Guardrails CQI Reporter | 13/7/2023 | 17/6/2026 | An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker. | |
| Modificada | Alta (7.5) | 1.1% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.8) | 4.3% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 1.3% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 38% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 2.6% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Media (4.8) | 0.54% | — | Phpgurukul Online Fire Reporting System | 10/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field. | |
| Modificada | Crítica (9.8) | 0.94% | — | Tise Parking WEB Report | 10/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Parking Web Report allows SQL Injection. This issue affects Parking Web Report: before 2.1. | |
| Modificada | Media (4.8) | 0.63% | — | Enzipe Prepost SEO | 10/7/2023 | 17/6/2026 | The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.66% | — | Techsneeze Dmarc Report | 22/6/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerabiliy in dmarcts-report-viewer dashboard versions 1.1 and thru commit 8a1d882b4c481a05e296e9b38a7961e912146a0f, allows unauthenticated attackers to execute arbitrary code via the org_name or domain values. | |
| Modificada | Media (4.8) | 0.37% | — | Onewebsite WP Repost | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in OneWebsite WP Repost plugin <= 0.1 versions. | |
| Modificada | Media (5.4) | 0.62% | — | Jenkins Maven Repository Server | 14/6/2023 | 17/6/2026 | Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (5.4) | 0.62% | — | Jenkins Maven Repository Server | 14/6/2023 | 17/6/2026 | Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in `pom.xml`. | |
| Modificada | Media (6.5) | 1.0% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Media (6.3) | 0.88% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (7.3) | 1.2% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Media (6.5) | 2.0% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Denial of Service Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 2.1% | 💥 PoC | Reportlab | 5/6/2023 | 17/6/2026 | Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. | |
| Modificada | Alta (7.8) | 0.22% | — | Intel System Usage Report | 10/5/2023 | 17/6/2026 | Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.2) | 85% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability |