Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation. | |
| Modificada | Alta (8.8) | 1.6% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution. | |
| Modificada | Crítica (9.8) | 1.1% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator. | |
| Modificada | Alta (8.8) | 1.3% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution. | |
| Modificada | Alta (7.5) | 0.57% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials. | |
| Modificada | Alta (8.8) | 0.55% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation. | |
| Modificada | Alta (7.5) | 0.74% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass. | |
| Modificada | Alta (7.8) | 0.16% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation. | |
| Modificada | Alta (8.8) | 0.66% | — | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Deltaww Infrasuite Device Master | 27/3/2023 | 17/6/2026 | Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary… | |
| Modificada | Media (5.4) | 0.49% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 2/3/2023 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within… | |
| Modificada | Alta (8.8) | 26% | — | Salesagility Suitecrm | 25/2/2023 | 17/6/2026 | Path traversal: '\..\filename' en el repositorio salesagility/suitecrm de GitHub anterior a 7.12.9. | |
| Modificada | Media (5.5) | 0.19% | — | IBM Maximo Application Suite | 24/2/2023 | 17/6/2026 | IBM Maximo Application Suite 8.8.0 y 8.9.0 almacena información potencialmente confidencial que podría ser leída por un usuario local. ID de IBM X-Force: 241584. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Multifunction Printer E525w Driver AND Software Suite | 21/2/2023 | 17/6/2026 | Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system | |
| Modificada | Alta (7.5) | 0.50% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 17/2/2023 | 17/6/2026 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587. | |
| Modificada | Baja (3.3) | 0.17% | — | Dell Command | Integration Suite FOR System Center | 13/2/2023 | 17/6/2026 | Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. | |
| Modificada | Media (4.9) | 0.55% | — | Dell Wyse Management Suite | 11/2/2023 | 17/6/2026 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized. | |
| Modificada | Media (6.5) | 0.51% | — | Dell Wyse Management Suite | 11/2/2023 | 17/6/2026 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities. | |
| Modificada | Media (4.9) | 0.55% | — | Dell Wyse Management Suite | 11/2/2023 | 17/6/2026 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized. | |
| Modificada | Media (4.9) | 0.55% | — | Dell Wyse Management Suite | 11/2/2023 | 17/6/2026 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized. | |
| Modificada | Media (4.9) | 0.55% | — | Dell Wyse Management Suite | 11/2/2023 | 17/6/2026 | Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users under administration and unassigned admins for which the group admin is not authorized. | |
| Modificada | Media (5.3) | 0.47% | — | Dell Wyse Management Suite | 11/2/2023 | 17/6/2026 | Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research. | |
| Modificada | Media (6.1) | 0.62% | — | Jsuites | 31/1/2023 | 17/6/2026 | Las versiones del paquete jsuites anteriores a la 5.0.1 son vulnerables a Cross-site Scripting (XSS) debido a una sanitización inadecuada de la entrada del usuario en la función Editor(). | |
| Modificada | Alta (8.8) | 0.99% | — | Deltaww Infrasuite Device Master | 26/1/2023 | 17/6/2026 | Existe una vulnerabilidad de escalada de privilegios en Delta Electronics InfraSuite Device Master 00.00.02a. Un usuario predeterminado 'Usuario', que está en el grupo 'Usuario de solo lectura', puede ver la contraseña de otro usuario predeterminado 'Administrador', que está en el grupo 'Administrador'. Esto permite… | |
| Modificada | Alta (7.5) | 0.63% | — | Oracle E-business Suite | 18/1/2023 | 17/6/2026 | Vulnerabilidad en el producto Oracle Applications DBA de Oracle E-Business Suite (componente: Java utils). Las versiones compatibles que se ven afectadas son 12.2.3-12.2.12. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer el DBA de… |