Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
2650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9) | 0.94% | — | Chatengine Project Chatengine | 6/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code. | |
| Modificada | Crítica (9.6) | 0.89% | — | Chatengine Project Chatengine | 6/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code. | |
| Modificada | Media (6.1) | 0.40% | — | Chatengine Project Chatengine | 6/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in username field in /WebContent/WEB-INF/lib/chatbox.jsp in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 0.56% | — | Chatengine Project Chatengine | 6/7/2023 | 17/6/2026 | SQL Injection vulnerability in textMessage parameter in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine v.1.0, allows attackers to gain sensitive information. | |
| Modificada | Alta (7.5) | 0.56% | — | Chatengine Project Chatengine | 6/7/2023 | 17/6/2026 | SQL Injection vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to gain sensitive information. | |
| Modificada | Media (5.4) | 0.37% | — | Chatengine Project Chatengine | 6/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to execute arbitrary code. | |
| Modificada | Media (4.9) | 3.0% | — | Zohocorp Manageengine Admanager Plus | 5/7/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. | |
| Modificada | Media (4.8) | 0.47% | — | Meowapps AI Engine | 27/6/2023 | 17/6/2026 | The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). | |
| Modificada | Crítica (9.8) | 26% | 💥 PoC | Blogengine.net | 26/6/2023 | 17/6/2026 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code. | |
| Modificada | Media (6.1) | 31% | 💥 Exploit | Blogengine.net | 21/6/2023 | 17/6/2026 | Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect. | |
| Modificada | Crítica (9.8) | 6.0% | 💥 PoC | Zohocorp Manageengine Adselfservice Plus | 20/6/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail… | |
| Modificada | Crítica (9.8) | 4.0% | — | Tdengine Grafana | 6/6/2023 | 17/6/2026 | The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary code execution within the github action context due to the insecure usage of `${{ github.event.pull_request.title }}` in a bash command within the GitHub workflow.… | |
| Modificada | Media (6.1) | 0.62% | — | Local Service Search Engine Management System Project Local Service Search Engine Management System | 31/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input… | |
| Modificada | Alta (8.8) | 0.25% | — | Wpmet Shopengine | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Wpmet ShopEngine plugin <= 4.1.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Chronoengine Chronoforms | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in chronoengine.Com Chronoforms plugin <= 7.0.9 versions. | |
| Modificada | Alta (8.8) | 0.23% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Microengine Mailform | 23/5/2023 | 17/6/2026 | MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. | |
| Modificada | Crítica (9.8) | 0.92% | — | Microengine Mailform | 23/5/2023 | 17/6/2026 | Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. | |
| Modificada | Media (5.5) | 0.23% | — | ABB Platform Engineering ToolsABB QCS 800xa FirmwareABB QCS Ac450 Firmware | 22/5/2023 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to… | |
| Modificada | Media (4.9) | 0.72% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid… | |
| Modificada | Media (4.9) | 0.77% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid… | |
| Modificada | Media (4.9) | 0.40% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,… | |
| Modificada | Media (4.9) | 0.49% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator… |