Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.76% | — | Open-xchange OX APP Suite | 29/5/2023 | 17/6/2026 | OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data. | |
| Modificada | Media (6.1) | 0.43% | — | Open-xchange OX APP Suite | 29/5/2023 | 17/6/2026 | OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title. | |
| Modificada | Media (6.1) | 0.43% | — | Open-xchange OX APP Suite | 29/5/2023 | 17/6/2026 | OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree. | |
| Modificada | Media (4.3) | 0.54% | — | Open-xchange OX APP Suite | 29/5/2023 | 17/6/2026 | OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book. | |
| Modificada | Media (4.3) | 0.50% | — | Open-xchange OX APP Suite | 29/5/2023 | 17/6/2026 | OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion." | |
| Modificada | Media (4.3) | 0.52% | — | Open-xchange OX APP Suite | 29/5/2023 | 17/6/2026 | OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user. | |
| Modificada | Media (5.3) | 0.55% | — | Open-xchange OX APP Suite | 29/5/2023 | 17/6/2026 | OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing. | |
| Modificada | Media (4.8) | 0.40% | — | Custom Field Suite Project Custom Field Suite | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions. | |
| Modificada | Crítica (9.8) | 5.9% | 💥 Exploit | Softexpert Excellence Suite | 12/5/2023 | 17/6/2026 | SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel NUC PRO Software Suite | 10/5/2023 | 17/6/2026 | Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel NUC PRO Software Suite | 10/5/2023 | 17/6/2026 | Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel NUC PRO Software Suite | 10/5/2023 | 17/6/2026 | Path traversal for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel NUC PRO Software Suite | 10/5/2023 | 17/6/2026 | Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel NUC PRO Software Suite | 10/5/2023 | 17/6/2026 | Improper access control for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.4) | 0.38% | — | Rymera Wholesale Suite | 9/5/2023 | 17/6/2026 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Rymera Web Co Wholesale Suite plugin <= 2.1.5 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Plugin-planet Dashboard Widget Suite | 6/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions. | |
| Modificada | Media (6.1) | 0.57% | — | Open-xchange OX APP Suite | 16/4/2023 | 17/6/2026 | OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger. | |
| Modificada | Media (4.3) | 0.46% | — | Open-xchange OX APP Suite | 15/4/2023 | 17/6/2026 | OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address). | |
| Modificada | Media (4.3) | 0.46% | — | Open-xchange OX APP Suite | 15/4/2023 | 17/6/2026 | OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list. | |
| Modificada | Media (6.1) | 0.43% | — | Open-xchange OX APP Suite | 15/4/2023 | 17/6/2026 | OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob. | |
| Modificada | Media (6.1) | 0.43% | — | Open-xchange OX APP Suite | 15/4/2023 | 17/6/2026 | OX App Suite before 7.10.6-rev20 allows XSS via upsell ads. | |
| Modificada | Alta (7.8) | 0.17% | — | Flexera Flexnet ManagerFlexera Flexnet Manager Suite 2015 | 29/3/2023 | 17/6/2026 | A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the local system. | |
| Modificada | Alta (7.8) | 0.31% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution. | |
| Modificada | Alta (8.8) | 0.65% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation. | |
| Modificada | Alta (8.8) | 0.83% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code. |