Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.4) | 0.37% | — | Anuko Time Tracker | 9/5/2023 | 17/6/2026 | Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Because of that, it was possible for a logged in user to enter notes with elements of JavaScript. Such script could then be executed in user… | |
| Modificada | Media (5.4) | 0.44% | — | Timersys WP Popups | 8/5/2023 | 17/6/2026 | The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to… | |
| Modificada | Media (4.8) | 0.44% | — | Byconsole Pickup | Delivery | Dine-in Date Time | 8/5/2023 | 17/6/2026 | The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.45% | — | Bytecodealliance Wasmtime | 27/4/2023 | 17/6/2026 | Wasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation of managing per-instance state, such as tables and memories, contains LLVM-level undefined behavior. This undefined behavior was found to cause runtime-level issues when compiled with LLVM 16 which… | |
| Modificada | Media (4.9) | 0.90% | — | Changingtec Mobile ONE Time Password | 27/4/2023 | 17/6/2026 | ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files. | |
| Modificada | Alta (7.2) | 0.97% | — | Meinbergglobal Lantime Firmware | 24/4/2023 | 17/6/2026 | In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands. | |
| Modificada | Media (4.8) | 0.39% | — | Codebangers ALL IN ONE Time Clock Lite | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Codebangers All in One Time Clock Lite plugin <= 1.3.320 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Timesheets-for-jira Timesheet Tracking | 17/4/2023 | 17/6/2026 | The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. | |
| Modificada | Media (4.8) | 0.44% | — | Dcac Time Sheets | 10/4/2023 | 17/6/2026 | The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.39% | — | Timersys WP Popups | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin <= 2.1.4.8 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Codepeople WP Time Slots Booking Form | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions. | |
| Modificada | Media (6.1) | 0.68% | — | Uptime Kuma Project Uptime Kuma | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint. | |
| Modificada | Media (5.3) | 2.5% | — | Ruby-lang RubyRuby-lang TimeDebian LinuxFedoraproject Fedora | 31/3/2023 | 17/6/2026 | A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2. | |
| Modificada | Alta (7.8) | 1.9% | 💥 PoC | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+9 | 27/3/2023 | 17/6/2026 | A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution. | |
| Modificada | Crítica (9.8) | 0.97% | — | DenoDeno RuntimeDeno Serde V8 | 24/3/2023 | 17/6/2026 | Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in the wild, as the only version affected… | |
| Modificada | Alta (8.8) | 0.88% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+12 | 23/3/2023 | 17/6/2026 | In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device. | |
| Modificada | Alta (8.8) | 1.0% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+11 | 23/3/2023 | 17/6/2026 | The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device. | |
| Modificada | Media (4.8) | 0.37% | — | Plustime Service Area Postcode Checker | 20/3/2023 | 17/6/2026 | Auth. (admin+) vulnerability in Second2none Service Area Postcode Checker plugin <= 2.0.8 versions. | |
| Modificada | Alta (7.5) | 0.80% | — | Crossplane-runtime | 9/3/2023 | 17/6/2026 | crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. An out of memory panic vulnerability has been discovered in affected versions. Applications that use the `Paved` type's `SetValue` method with user provided input without proper validation might use… | |
| Modificada | Media (4.3) | 0.62% | — | Bytecodealliance Cranelift-codegenBytecodealliance Wasmtime | 8/3/2023 | 17/6/2026 | wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than… | |
| Modificada | Crítica (9.9) | 1.3% | — | Bytecodealliance Cranelift-codegenBytecodealliance Wasmtime | 8/3/2023 | 17/6/2026 | wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective address. This bug means that, with default… | |
| Modificada | Alta (8.8) | 0.79% | — | Class AND Exam Timetabling System Project Class AND Exam Timetabling System | 26/2/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index3.php of the component POST Parameter Handler. The manipulation of the argument password leads to sql injection. The attack can be… | |
| Modificada | Alta (7.5) | 0.60% | — | Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+6 | 23/2/2023 | 17/6/2026 | The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol. | |
| Modificada | Media (5.4) | 0.47% | — | Uptime-kuma Project Uptime-kuma | 21/2/2023 | 17/6/2026 | Uptime Kuma es una herramienta de monitoreo autohospedada. En versiones anteriores a la 1.20.0, el parámetro "nombre" de Uptime Kuma permite un ataque XSS persistente. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad. |