Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
2650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 7.9% | — | Zohocorp Manageengine Admanager Plus | 17/8/2023 | 17/6/2026 | ADManager Plus versión 7182 y anteriores de ManageEngine de Zoho divulgaron las contraseñas predeterminadas para la restauración de cuentas de dominios no autorizadas a los usuarios autenticados. | |
| Modificada | Media (6.5) | 0.74% | — | Cisco Identity Services Engine | 16/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit… | |
| Modificada | Media (6.1) | 3.1% | — | Zohocorp Manageengine Password Manager PRO | 11/8/2023 | 17/6/2026 | Una vulnerabilidad de Cross-Site Scripting (XSS) en la función Query Report en Zoho ManageEngine Password Manager Pro versión 11001, permite a atacantes remotos ejecutar código arbitrario y robar cookies a través de un payload JavaScript manipulado. | |
| Modificada | Media (4.4) | 0.20% | — | Intel Converged Security Management Engine Firmware | 11/8/2023 | 17/6/2026 | La validación de entrada inadecuada en el firmware de algunos Intel(R) Converged Security and Management Engine anteriores a las versiones 15.0.45 y 16.1.27 puede permitir que un usuario con privilegios habilite potencialmente la denegación de servicio mediante acceso local. | |
| Modificada | Alta (7.5) | 0.66% | — | Intel Converged Security Management Engine Firmware | 11/8/2023 | 17/6/2026 | La validación de entrada inadecuada en algunos firmware para Intel(R) AMT e Intel(R) Standard Manageability antes de las versiones 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45 y 16.1.27 en Intel (R) CSME puede permitir que un usuario no autenticado habilite potencialmente la denegación de servicio a través… | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Converged Security Management Engine Firmware | 11/8/2023 | 17/6/2026 | Un control de acceso inadecuado en el instalador del software Intel(R) CSME anterior a la versión 2239.3.7.0 puede permitir que un usuario autenticado habilite potencialmente una escalada de privilegios mediante acceso local. | |
| Modificada | Media (6.1) | 2.3% | — | Zohocorp Manageengine Applications Manager | 10/8/2023 | 17/6/2026 | Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. | |
| Modificada | Alta (7.5) | 3.9% | — | Zohocorp Manageengine Adaudit Plus | 7/8/2023 | 17/6/2026 | The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour." | |
| Modificada | Media (6.5) | 3.7% | — | Zohocorp Manageengine Admanager Plus | 4/8/2023 | 17/6/2026 | ADManager Plus de ManageEngine de Zoho a través de 7201 permiten a los usuarios autenticados hacerse cargo de la cuenta de otro usuario a través de la divulgación de información sensible. | |
| Modificada | Alta (8.8) | 1.1% | — | Zohocorp Manageengine Network Configuration Manager | 4/8/2023 | 17/6/2026 | Se ha descubierto un problema en Network Configuration Manager 12.6.165 de ManageEngine de Zoho. El WebSocket endpoint permite Cross-site WebSocket hijacking. | |
| Modificada | Media (5.4) | 2.2% | — | Zohocorp Manageengine Supportcenter Plus | 28/7/2023 | 17/6/2026 | Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module. | |
| Modificada | Media (6.5) | 0.68% | — | Tdengine | 25/7/2023 | 17/6/2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF nested query. This issue affects TDengine Databases which let users connect and run arbitrary queries. Version 3.0.7.1 has a patch for this issue. | |
| Modificada | Media (5.4) | 0.36% | — | Nesote Inout Search Engine AI Edition | 16/7/2023 | 17/6/2026 | A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this… | |
| Modificada | Crítica (9.8) | 1.1% | — | Extremenetworks IQ Engine | 15/7/2023 | 17/6/2026 | IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit. | |
| Modificada | Alta (7.5) | 0.56% | — | Bitdefender Engines | 14/7/2023 | 17/6/2026 | An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bitdefender Engines version 7.94791 and lower. | |
| Modificada | Alta (7.5) | 0.57% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.65% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.66% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message | |
| Modificada | Alta (7.5) | 0.65% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Modificada | Alta (7.5) | 0.60% | — | Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station | 13/7/2023 | 17/6/2026 | Experion server may experience a DoS due to a stack overflow when handling a specially crafted message. | |
| Modificada | Alta (7) | 0.27% | — | Microsoft Malware Protection Engine | 11/7/2023 | 17/6/2026 | Microsoft Defender Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 0.27% | — | Wpengine PHP Compatibility Checker | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Engine PHP Compatibility Checker plugin <= 1.5.2 versions. | |
| Modificada | Media (5.4) | 1.9% | — | Zohocorp Manageengine Adaudit Plus | 7/7/2023 | 17/6/2026 | Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field. | |
| Modificada | Media (5.4) | 3.5% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 7/7/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications. | |
| Modificada | Crítica (9) | 0.94% | — | Chatengine Project Chatengine | 6/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code. |