Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

2615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.95%—Deltaww Infrasuite Device Master10/7/202317/6/2026
​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.
ModificadaMedia (5.4)0.57%—Gis3w G3w-suite7/7/202317/6/2026
A Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the description parameter.
AnalizadaCrítica (9)77%⚠ Explotación activa💥 ExploitSynacor Zimbra Collaboration Suite6/7/202317/6/2026
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.
ModificadaAlta (8.8)1.3%—Open-xchange Appsuite Backend20/6/202317/6/2026
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary code could be injected that is being executed when processing the request. A check…
ModificadaMedia (5)0.78%—Open-xchange Appsuite Backend20/6/202317/6/2026
It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system user. This was limited to specific…
ModificadaMedia (4.3)1.1%—Open-xchange Appsuite Backend20/6/202317/6/2026
When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted POP3 server response to reasonable…
ModificadaMedia (4.3)1.1%—Open-xchange Appsuite Backend20/6/202317/6/2026
When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted IMAP server response to reasonable…
ModificadaMedia (4.3)1.1%—Open-xchange Appsuite Backend20/6/202317/6/2026
When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted SMTP server response to reasonable…
ModificadaMedia (4.3)0.84%—Open-xchange Appsuite Backend20/6/202317/6/2026
IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight about topology and running services. We…
ModificadaMedia (5.3)0.79%—Open-xchange Appsuite Backend20/6/202317/6/2026
Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are…
ModificadaMedia (6.5)0.98%—Open-xchange Appsuite Backend20/6/202317/6/2026
Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not explicitly shared with other users. No…
ModificadaBaja (3.3)0.33%—Open-xchange Appsuite Backend20/6/202317/6/2026
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known.
ModificadaBaja (2.4)0.36%—Dominionvoting Democracy Suite19/6/202317/6/2026
A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in which ballots were cast from public ballot-level data, allowing deanonymization of voted ballots, in several types of scenarios. This issue…
ModificadaMedia (4.8)0.55%—Salesagility Suitecrm16/6/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
ModificadaAlta (7.2)0.79%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 podría permitir a un usuario con privilegios cargar archivos maliciosos con formatos peligrosos que pueden procesarse automáticamente en el entorno del producto. ID de IBM X-Force: 228586.
ModificadaAlta (7.5)0.85%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 utiliza una configuración de bloqueo de cuentas inadecuada que podría permitir a un atacante remoto forzar las credenciales de las cuentas. ID de IBM X-Force: 228510.
ModificadaAlta (8.8)1.4%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios en el sistema enviando una solicitud especialmente manipulada. ID de IBM X-Force: 228439.
ModificadaAlta (7.5)0.77%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 podría permitir a un atacante provocar una denegación de servicio debido al consumo incontrolado de recursos. ID de IBM X-Force: 228588.
ModificadaAlta (8.1)0.50%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 especifica permisos para un recurso crítico para la seguridad de una forma que permite que dicho recurso sea leído o modificado por actores no deseados. ID de IBM X-Force: 228571.
ModificadaMedia (6.5)0.34%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 almacena las credenciales de usuario en texto sin formato que puede leer un usuario autenticado. ID de IBM X-Force: 228567.
ModificadaMedia (5.4)0.41%—Softexpert Excellence Suite14/6/202317/6/2026
SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens.
ModificadaMedia (5.3)0.64%—IBM Maximo Application SuiteIBM Maximo Asset Management5/6/202317/6/2026
IBM Maximo Asset Management v7.6.1.2, v7.6.1.3 e IBM Maximo Application Suite v8.8.0 almacenan información confidencial en parámetros de URL. Esto puede dar lugar a la divulgación de información si partes no autorizadas tienen acceso a las URL a través de los registros del servidor, el encabezado de referencia o el…
ModificadaMedia (5.9)0.34%—IBM Maximo Application Suite5/6/202317/6/2026
IBM Maximo Application Suite - Manage Component v8.8.0 y v8.9.0 transmite información confidencial en texto claro que podría ser interceptada por un atacante mediante técnicas de "man in the middle". IBM X-Force ID: 249208.
ModificadaMedia (4.2)0.36%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite antes de la versión 7.10.6-rev37 no impone la verificación en dos pasos para todos los servicios finales, como por ejemplo: leer desde un dispositivo, leer datos de contacto y el cambio de nombre de símbolos.
ModificadaMedia (4.3)0.67%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of header data.
Orbitaley — Vulnerabilidades