Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2814▼ 267 respecto a la semana anterior
Críticas / altas1316▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

2803 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.9%—OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+730/5/202317/6/2026
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
ModificadaAlta (7.8)0.36%—Actionlauncher Action Launcher30/5/202317/6/2026
An issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent string to function update.
ModificadaMedia (5.5)0.34%—Actionlauncher Action Launcher30/5/202317/6/2026
An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function insert.
ModificadaMedia (6.1)2.2%💥 ExploitSquarepiginteractive Fusioninvoice25/5/202317/6/2026
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
ModificadaAlta (7.5)0.82%—Miniorange Active Directory Integration / Ldap Integration15/5/202317/6/2026
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
ModificadaMedia (5.4)0.46%—Activecampaign15/5/202317/6/2026
The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (8.8)0.25%—Wpmart Interactive SVG Image MAP Builder10/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions.
ModificadaMedia (6.1)0.41%—Properfraction Profilepress3/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
ModificadaMedia (5.4)0.41%—Properfraction Profilepress3/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
ModificadaAlta (7.5)0.60%—IBM Infosphere Information ServerIBM JavaIBM Websphere Application ServerIBM Z/transaction Processing Facility29/4/202317/6/2026
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.
ModificadaMedia (5.4)0.37%—IBM Financial Transaction Manager FOR Multiplatform29/4/202317/6/2026
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239707.
ModificadaMedia (6.5)0.29%—Gradle Build Action28/4/202317/6/2026
Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration cache enabled, potentially exposing secrets configured for the…
ModificadaAlta (7.5)2.4%💥 PoCLinux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+425/4/202317/6/2026
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the…
ModificadaMedia (5.4)0.39%—Interactive GEO Maps Project Interactive GEO Maps25/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Carlos Moreira Interactive Geo Maps plugin <= 1.5.8 versions.
ModificadaMedia (6.1)0.54%—Mybb Active Threads24/4/202317/6/2026
In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.
ModificadaAlta (8.8)0.27%—Areteit Activity Reactions FOR Buddypress23/4/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 versions.
ModificadaMedia (6.3)0.65%—Vmware Spring SecurityNetapp Active IQ Unified Manager19/4/202317/6/2026
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the…
ModificadaMedia (5.3)0.43%—Discourse Reactions19/4/202317/6/2026
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable…
ModificadaMedia (5.3)2.5%—Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython19/4/202317/6/2026
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after…
ModificadaMedia (5.3)1.3%💥 PoCEclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+218/4/202317/6/2026
Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cookie parsing mechanism. If Jetty sees a cookie VALUE that starts with `"` (double quote), it will…
ModificadaMedia (5.3)1.3%💥 PoCOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core PolicyOracle Mysql ConnectorsNetapp Active IQ Unified Manager+218/4/202317/6/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require…
ModificadaMedia (4.9)1.4%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/4/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Components Services). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los…
ModificadaMedia (4.9)1.4%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/4/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Partition). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques…
ModificadaMedia (4.9)1.5%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/4/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Partition). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques…
ModificadaMedia (4.4)1.4%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/4/202317/6/2026
Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Components Services). Las versiones afectadas son 8.0.32 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con altos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los…