Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 1.2% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: InnoDB). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con altos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques exitosos de esta… | |
| Modificada | Media (4.9) | 1.3% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: InnoDB). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques exitosos de… | |
| Modificada | Baja (3.1) | 0.95% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7… | |
| Modificada | Media (4.4) | 1.3% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Replication). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con altos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… | |
| Modificada | Alta (8.8) | 0.25% | — | Inactive User Deleter Project Inactive User Deleter | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Korol Yuriy aka Shra Inactive User Deleter plugin <= 1.59 versions. | |
| Modificada | Media (5.9) | 0.46% | — | Jenkins Active Directory | 12/7/2023 | 17/6/2026 | Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory… | |
| Modificada | Media (4.3) | 0.56% | — | Vuukle Comments, Reactions, Share Bar, Revenue | 12/7/2023 | 17/6/2026 | The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for… | |
| Modificada | Media (6.1) | 0.34% | — | Activeitzone Active Ecommerce CMS | 4/7/2023 | 17/6/2026 | A vulnerability was found in Active It Zone Active eCommerce CMS 6.5.0. It has been declared as problematic. This vulnerability affects unknown code of the file /ecommerce/support_ticket of the component Create Ticket Page. The manipulation of the argument details with the input <script>alert(1)</script> leads to… | |
| Modificada | Media (6.5) | 8.3% | 💥 PoC | Linux KernelNetapp Active IQ Unified ManagerDebian Linux | 30/6/2023 | 17/6/2026 | A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system. | |
| Modificada | Alta (7.5) | 0.53% | — | Miniorange Active Directory Integration / Ldap Integration | 29/6/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to… | |
| Modificada | Alta (7.5) | 2.5% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33… | |
| Modificada | Alta (7.5) | 0.88% | — | ISC BindNetapp Active IQ Unified ManagerNetapp H500s FirmwareNetapp H700s Firmware+3 | 21/6/2023 | 17/6/2026 | A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and… | |
| Modificada | Alta (7.5) | 3.6% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of… | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Factorytalk Transaction Manager | 13/6/2023 | 17/6/2026 | A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage condition, causing intermittent application… | |
| Modificada | Media (4.3) | 0.30% | — | Wpwhitesecurity WP Activity LOG | 9/6/2023 | 17/6/2026 | The WP Activity Log for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. This is due to missing or incorrect nonce validation on the ajax_run_cleanup function. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted they… | |
| Modificada | Media (4.3) | 0.21% | — | Wpwhitesecurity WP Activity LOG | 9/6/2023 | 17/6/2026 | The WP Activity Log Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. This is due to missing or incorrect nonce validation on the ajax_switch_db function. This makes it possible for unauthenticated attackers to make changes to the plugin's settings via a… | |
| Modificada | Media (4.3) | 0.39% | — | Wpwhitesecurity WP Activity LOG | 9/6/2023 | 17/6/2026 | The WP Activity Log Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_switch_db function in versions up to, and including, 4.5.0. This makes it possible for authenticated attackers with subscriber-level or higher to make changes to the… | |
| Modificada | Media (4.3) | 0.55% | — | Wpwhitesecurity WP Activity LOG | 9/6/2023 | 17/6/2026 | The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_ajax_call function in versions up to, and including, 4.5.0. This makes it possible for authenticated attackers, with subscriber-level access or higher, to obtain a list of users with accounts… | |
| Modificada | Media (6.5) | 0.42% | — | Miniorange Active Directory Integration / Ldap Integration | 9/6/2023 | 17/6/2026 | The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied… | |
| Modificada | Media (4.9) | 0.85% | — | Miniorange Active Directory Integration / Ldap Integration | 9/6/2023 | 17/6/2026 | The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Modificada | Media (6.5) | 0.97% | — | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+11 | 7/6/2023 | 17/6/2026 | The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and… | |
| Modificada | Alta (7.3) | 0.83% | — | Wpwhitesecurity WP Activity LOG | 7/6/2023 | 17/6/2026 | The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to run the setup wizard (if it has not been run previously) and access plugin… | |
| Modificada | Crítica (9.8) | 65% | 💥 Exploit | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+12 | 7/6/2023 | 17/6/2026 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <=… | |
| Modificada | Media (6.1) | 0.29% | — | Contact Form AND Calls TO Action BY Vcita | 3/6/2023 | 17/6/2026 | El plugin Contact Form y el Calls To Action by vcita para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 2.6.4 inclusive. Esto se debe a la falta de validación nonce en el archivo "vcita-callback.php". Esto hace posible que los atacantes no autenticados modifiquen la configuración del… | |
| Modificada | Media (5.4) | 0.52% | — | Contact Form AND Calls TO Action BY Vcita | 3/6/2023 | 17/6/2026 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts… |