Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.25% | — | Weightbasedshipping Woocommerce Weight Based Shipping | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in weightbasedshipping.Com WooCommerce Weight Based Shipping plugin <= 5.4.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Sigmaplugin Advanced Database Cleaner | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions. | |
| Modificada | Crítica (9.6) | 0.60% | — | Metabase | 18/5/2023 | 17/6/2026 | Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions to a database–but affected versions of Metabase didn't enforce that requirement. This lack of enforcement meant that: Anyone–including… | |
| Modificada | Crítica (9.1) | 0.75% | — | Vmware Greenplum Database | 15/5/2023 | 17/6/2026 | Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file writes. An attacker can use this vulnerability to overwrite… | |
| Modificada | Media (6.7) | 0.16% | — | Intel Battery Life Diagnostic ToolIntel Oneapi Base ToolkitIntel SOC Watch | 12/5/2023 | 17/6/2026 | Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Oneapi AI Analytics ToolkitIntel Oneapi Base ToolkitIntel Oneapi DL Framework Developer ToolkitIntel Oneapi HPC Toolkit+2 | 12/5/2023 | 17/6/2026 | Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 13% | 💥 PoC | Linux KernelRedhat Enterprise LinuxNetapp HCI Baseboard Management Controller | 8/5/2023 | 17/6/2026 | In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Membership Database Project Membership Database | 8/5/2023 | 17/6/2026 | The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelNetapp HCI Baseboard Management Controller | 1/5/2023 | 17/6/2026 | A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past… | |
| Modificada | Media (5.5) | 3.3% | — | Visam Vbase | 26/4/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (6.5) | 1.3% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | |
| Modificada | Alta (7.5) | 0.81% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | No exception handling vulnerability which revealed sensitive or excessive information to users. | |
| Modificada | Alta (7) | 0.36% | — | Linux KernelNetapp HCI Baseboard Management Controller | 24/4/2023 | 17/6/2026 | A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel. | |
| Modificada | Media (5.3) | 0.51% | — | Oracle Essbase | 18/4/2023 | 17/6/2026 | Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the… | |
| Modificada | Media (5.3) | 0.51% | — | Oracle Essbase | 18/4/2023 | 17/6/2026 | Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the… | |
| Modificada | Media (5.3) | 0.51% | — | Oracle Essbase | 18/4/2023 | 17/6/2026 | Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the… | |
| Modificada | Media (6.8) | 0.54% | — | Oracle Database | 18/4/2023 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having User Account privilege with network access via TLS to compromise Java VM. Successful attacks of this vulnerability can result… | |
| Modificada | Media (6.8) | 0.67% | — | Oracle Database Recovery Manager | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local SYSDBA privilege with network access via Oracle Net to compromise Oracle Database Recovery… | |
| Modificada | Media (5.7) | 0.38% | — | Uniswap Web3-react Coinbase-walletUniswap Web3-react Eip1193Uniswap Web3-react MetamaskUniswap Web3-react Walletconnect | 17/4/2023 | 17/6/2026 | @web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may be incorrect. In an application, this means that any data derived from `chainId`… | |
| Analizada | Alta (8.8) | 41% | ⚠ Explotación activa💥 PoC | Google ChromeDebian LinuxFedoraproject FedoraCouchbase Server | 14/4/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.72% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (8.2) | 1.2% | — | Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+2 | 10/4/2023 | 17/6/2026 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,… |