Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
2803 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.0% | — | Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+5 | 30/3/2023 | 17/6/2026 | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation… | |
| Modificada | Media (6.1) | 0.41% | — | Properfraction Profilepress | 29/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin <= 4.5.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wpmart Interactive SVG Image MAP Builder | 28/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions. | |
| Modificada | Media (5.3) | 0.95% | — | Sudo Project SudoNetapp Active IQ Unified Manager | 16/3/2023 | 17/6/2026 | Sudo before 1.9.13 does not escape control characters in sudoreplay output. | |
| Modificada | Media (5.3) | 0.92% | — | Sudo Project SudoNetapp Active IQ Unified Manager | 16/3/2023 | 17/6/2026 | Sudo before 1.9.13 does not escape control characters in log messages. | |
| Modificada | Baja (3.3) | 0.19% | — | IBM Financial Transaction Manager | 15/3/2023 | 17/6/2026 | IBM Financial Transaction Manager for High Value Payments for Multi-Platform 3.2.0 through 3.2.10 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 183329. | |
| Modificada | Alta (8.8) | 1.6% | — | Github-slug-action Project Github-slug-action | 13/3/2023 | 17/6/2026 | github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workflow. Starting in version 4.0.0` and prior to version 4.4.1, this action uses the `github.head_ref` parameter in an insecure way. This vulnerability can be triggered by any user on GitHub on any… | |
| Modificada | Alta (8.8) | 0.58% | — | IBM Financial Transaction Manager | 10/3/2023 | 17/6/2026 | IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954. | |
| Modificada | Alta (7.5) | 0.75% | — | IBM Financial Transaction Manager | 1/3/2023 | 17/6/2026 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Financial Transaction Manager | 1/3/2023 | 17/6/2026 | IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953. | |
| Modificada | Media (6.5) | 0.41% | — | Netapp Active IQ Unified Manager | 28/2/2023 | 17/6/2026 | Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors. | |
| Modificada | Media (4.8) | 0.34% | — | Netapp Active IQ Unified Manager | 28/2/2023 | 17/6/2026 | Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows administrative users to perform a Stored Cross-Site Scripting (XSS) attack. | |
| Modificada | Alta (7.5) | 0.66% | — | User Activity Project User Activity | 27/2/2023 | 17/6/2026 | The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing | |
| Modificada | Media (6.5) | 0.86% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp H300s Firmware+4 | 23/2/2023 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is… | |
| Modificada | Crítica (9.1) | 0.86% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp H300s Firmware+4 | 23/2/2023 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL.… | |
| Modificada | Media (5.5) | 0.26% | — | Redhat ResteasyNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 17/2/2023 | 17/6/2026 | In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user. | |
| Modificada | Alta (7.5) | 20% | 💥 PoC | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+2 | 17/2/2023 | 17/6/2026 | Un problema en el componente urllib.parse de Python anterior a 3.11.4 permite a los atacantes eludir los métodos de listas de bloqueo proporcionando una URL que comienza con caracteres en blanco. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Media (6.1) | 0.60% | — | Actionpack Project ActionpackRubyonrails Rails | 9/2/2023 | 17/6/2026 | An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a… | |
| Modificada | Alta (7.5) | 1.7% | — | Activesupport Project Activesupport | 9/2/2023 | 17/6/2026 | A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a… | |
| Modificada | Alta (8.8) | 2.2% | — | Activerecord Project Activerecord | 9/2/2023 | 17/6/2026 | A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious user input is passed to either the `annotate` query method, the `optimizer_hints` query method, or through the QueryLogs interface which automatically adds annotations, it may be sent to the database… | |
| Modificada | Alta (7.5) | 1.3% | — | Activerecord Project Activerecord | 9/2/2023 | 17/6/2026 | A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer values against numeric values can result… | |
| Modificada | Media (5.4) | 0.52% | — | Interactive GEO Maps Project Interactive GEO Maps | 7/2/2023 | 17/6/2026 | The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the action content parameter in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor… | |
| Modificada | Crítica (9.8) | 2.1% | — | Schneider-electric Interactive Graphical Scada System | 1/2/2023 | 17/6/2026 | A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Schneider-electric Interactive Graphical Scada System | 1/2/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073) |