Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

2615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.76%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.
ModificadaMedia (6.1)0.43%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
ModificadaMedia (6.1)0.43%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
ModificadaMedia (4.3)0.54%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.
ModificadaMedia (4.3)0.50%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."
ModificadaMedia (4.3)0.52%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.
ModificadaMedia (5.3)0.55%—Open-xchange OX APP Suite29/5/202317/6/2026
OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.
ModificadaMedia (4.8)0.40%—Custom Field Suite Project Custom Field Suite18/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matt Gibbs Custom Field Suite plugin <= 2.6.2.1 versions.
ModificadaCrítica (9.8)5.9%💥 ExploitSoftexpert Excellence Suite12/5/202317/6/2026
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.
ModificadaAlta (7.8)0.15%—Intel NUC PRO Software Suite10/5/202317/6/2026
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.15%—Intel NUC PRO Software Suite10/5/202317/6/2026
Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel NUC PRO Software Suite10/5/202317/6/2026
Path traversal for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Intel NUC PRO Software Suite10/5/202317/6/2026
Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.15%—Intel NUC PRO Software Suite10/5/202317/6/2026
Improper access control for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.4)0.38%—Rymera Wholesale Suite9/5/202317/6/2026
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Rymera Web Co Wholesale Suite plugin <= 2.1.5 versions.
ModificadaMedia (4.8)0.37%—Plugin-planet Dashboard Widget Suite6/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions.
ModificadaMedia (6.1)0.57%—Open-xchange OX APP Suite16/4/202317/6/2026
OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.
ModificadaMedia (4.3)0.46%—Open-xchange OX APP Suite15/4/202317/6/2026
OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address).
ModificadaMedia (4.3)0.46%—Open-xchange OX APP Suite15/4/202317/6/2026
OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.
ModificadaMedia (6.1)0.43%—Open-xchange OX APP Suite15/4/202317/6/2026
OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
ModificadaMedia (6.1)0.43%—Open-xchange OX APP Suite15/4/202317/6/2026
OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.
ModificadaAlta (7.8)0.17%—Flexera Flexnet ManagerFlexera Flexnet Manager Suite 201529/3/202317/6/2026
A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects the inventory gathering components and can be exploited by local users to perform certain actions with elevated privileges on the local system.
ModificadaAlta (7.8)0.31%—Deltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
ModificadaAlta (8.8)0.65%—Deltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.
ModificadaAlta (8.8)0.83%—Deltaww Infrasuite Device Master27/3/202317/6/2026
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.