Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
1921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Xxyopen Novel-plus | 11/9/2023 | 17/6/2026 | novel-plus 3.6.2 es vulnerable a la inyección SQL. | |
| Modificada | Media (6.8) | 25% | — | Zohocorp Manageengine Adselfservice Plus | 6/9/2023 | 17/6/2026 | ManageEngine ADSelfService Plus GINA Client Verificación insuficiente de autenticidad de datos Vulnerabilidad de omisión de autenticación. Esta vulnerabilidad permite a atacantes físicamente presentes ejecutar código arbitrario en instalaciones afectadas de ManageEngine ADSelfService Plus. No se requiere autenticación… | |
| Modificada | Media (4.8) | 0.36% | — | Gopiplus Wp-tell-a-friend-popup-form | 4/9/2023 | 17/6/2026 | Vulnerabilidad de Coss-Site Scripting (XSS) autenticada (con permisos de admin o superiores) almacenada en el plugin Gopi Ramasamy wp tell a friend popup form en versiones inferiores e incluyendo la 7.1. | |
| Analizada | Media (4.9) | 3.8% | — | Zohocorp Manageengine Admanager Plus | 31/8/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus anterior a 7203 permite a los usuarios de Técnico de Mesa de Ayuda leer archivos arbitrarios en la máquina donde está instalado este producto. | |
| Modificada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+13 | 28/8/2023 | 17/6/2026 | Zoho ManageEngine Active Directory 360 versiones 4315 e inferiores, ADAudit Plus 7202 e inferiores, ADManager Plus 7200 e inferiores, Asset Explorer 6993 e inferiores y 7xxx 7002 e inferiores, Cloud Security Plus 4161 e inferiores, Data Security Plus 6110 e inferiores, Eventlog Analyzer 12301 y siguientes, Exchange… | |
| Modificada | Media (5.5) | 0.41% | — | Notepad-plus-plus Notepad++ | 25/8/2023 | 17/6/2026 | Notepad++ es un editor de código fuente gratuito y de código abierto. Las versiones 8.5.6 y anteriores son vulnerables al desbordamiento de lectura del búfer de montón en `FileManager::detectLanguageFromTextBegining`. La explotabilidad de este problema no está clara. Potencialmente, puede ser utilizado para filtrar… | |
| Modificada | Media (5.5) | 0.50% | — | Notepad-plus-plus Notepad++ | 25/8/2023 | 17/6/2026 | Notepad++ es un editor de código fuente gratuito y de código abierto. Las versiones 8.5.6 y anteriores son vulnerables al desbordamiento global de lectura de búfer en `nsCodingStateMachine::NextStater`. La explotabilidad de este problema no está clara. Potencialmente, puede utilizarse para filtrar información de… | |
| Modificada | Media (5.5) | 0.38% | — | Notepad-plus-plus Notepad++ | 25/8/2023 | 17/6/2026 | Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of… | |
| Modificada | Alta (7.8) | 0.52% | 💥 PoC | Notepad-plus-plus Notepad++ | 25/8/2023 | 17/6/2026 | Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++. | |
| Modificada | Alta (7.5) | 1.1% | — | Cpplusworld Cp-vnr-3104 FirmwareCpplusworld Cp-vnr-3108 FirmwareCpplusworld Cp-vnr-3208 Firmware | 24/8/2023 | 17/6/2026 | The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability… | |
| Modificada | Media (5.3) | 0.69% | — | Cpplusworld Cp-uvr-1601e1-hc FirmwareCpplusworld Cp-uvr-0401l1-4kh FirmwareCpplusworld Cp-uvr-0401l1b-4kh FirmwareCpplusworld Cp-uvr-0801f1-hc Firmware+5 | 24/8/2023 | 17/6/2026 | The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this… | |
| Modificada | Media (6.5) | 7.9% | — | Zohocorp Manageengine Admanager Plus | 17/8/2023 | 17/6/2026 | ADManager Plus versión 7182 y anteriores de ManageEngine de Zoho divulgaron las contraseñas predeterminadas para la restauración de cuentas de dominios no autorizadas a los usuarios autenticados. | |
| Modificada | Media (6.1) | 0.38% | — | Updraftplus Updraft | 17/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions. | |
| Modificada | Baja (3.9) | 0.24% | — | Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+107 | 16/8/2023 | 17/6/2026 | Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit this vulnerability in order to modify a security-critical UEFI variable without knowledge of the BIOS administrator. | |
| Modificada | Media (6.3) | 0.19% | — | Dell Alienware M15 R7 FirmwareDell Alienware M16 FirmwareDell Alienware M18 FirmwareDell Chengming 3900 Firmware+238 | 16/8/2023 | 17/6/2026 | Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system. | |
| Modificada | Crítica (9.8) | 0.72% | — | Xxyopen Novel-plus | 14/8/2023 | 9/7/2026 | Se descubrió que novel-plus v3.6.2 contenía una vulnerabilidad de inyección SQL. | |
| Modificada | Crítica (9.8) | 0.76% | — | Oneplus Store | 10/8/2023 | 17/6/2026 | A remote code execution vulnerability in the webview component of OnePlus Store app. | |
| Modificada | Baja (3.3) | 0.29% | — | Ffri Dual SafeFfri YaraiSoliton Infotrace Mark II Malware ProtectionSoliton Zerona+4 | 9/8/2023 | 17/6/2026 | "FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0,… | |
| Modificada | Alta (7.5) | 3.9% | — | Zohocorp Manageengine Adaudit Plus | 7/8/2023 | 17/6/2026 | The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour." | |
| Modificada | Media (6.5) | 3.7% | — | Zohocorp Manageengine Admanager Plus | 4/8/2023 | 17/6/2026 | ADManager Plus de ManageEngine de Zoho a través de 7201 permiten a los usuarios autenticados hacerse cargo de la cuenta de otro usuario a través de la divulgación de información sensible. | |
| Modificada | Media (5.4) | 2.2% | — | Zohocorp Manageengine Supportcenter Plus | 28/7/2023 | 17/6/2026 | Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Srbtranslatin Project SrbtranslatinUpdraftplus Wp-optimize | 10/7/2023 | 17/6/2026 | The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability. | |
| Modificada | Media (5.4) | 1.9% | — | Zohocorp Manageengine Adaudit Plus | 7/7/2023 | 17/6/2026 | Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field. | |
| Modificada | Media (5.4) | 3.5% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 7/7/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications. | |
| Modificada | Media (4.9) | 3.0% | — | Zohocorp Manageengine Admanager Plus | 5/7/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. |