Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1904 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.35% | — | Acronis AgentAcronis Cyber Protect | 18/5/2023 | 17/6/2026 | Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984. | |
| Modificada | Alta (7.8) | 0.16% | — | Acronis AgentAcronis Cyber Protect | 18/5/2023 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984. | |
| Modificada | Alta (7.5) | 0.40% | — | Acronis AgentAcronis Cyber Protect | 18/5/2023 | 17/6/2026 | Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984. | |
| Modificada | Media (6.5) | 0.58% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method. | |
| Modificada | Media (4.3) | 0.50% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (4.8) | 0.37% | — | Useragent-spy Project Useragent-spy | 11/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fernando Briano UserAgent-Spy plugin <= 1.3.1 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Agentevolution Impress Listings | 10/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Agent Evolution IMPress Listings plugin <= 2.6.2 versions. | |
| Modificada | Alta (7.5) | 0.34% | — | Acronis Agent | 26/4/2023 | 17/6/2026 | Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 30161. | |
| Modificada | Alta (7.5) | 0.72% | — | Rapid7 Insight Agent | 26/4/2023 | 17/6/2026 | Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This… | |
| Modificada | Baja (3.7) | 1.0% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability… | |
| Modificada | Media (5.9) | 1.5% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows… | |
| Modificada | Media (5.9) | 1.4% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows… | |
| Modificada | Media (5.3) | 2.5% | 💥 PoC | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows… | |
| Modificada | Baja (3.7) | 1.2% | — | Oracle GraalvmOracle JDKOracle JREDebian Linux+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Difficult to exploit vulnerability… | |
| Modificada | Baja (3.7) | 1.2% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability… | |
| Modificada | Alta (7.4) | 1.3% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows… | |
| Modificada | Alta (7) | 0.17% | — | Qualys Cloud Agent | 18/4/2023 | 17/6/2026 | Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (macOS 10.15 and older) versions. Attackers may exploit incorrect file permissions to give them ROOT command execution privileges on the host.… | |
| Modificada | Alta (7) | 0.13% | — | Qualys Cloud Agent | 18/4/2023 | 17/6/2026 | A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges limited on the local machine during uninstallation of the Qualys Cloud Agent for Windows. Attackers may gain SYSTEM level privileges on that asset to run… | |
| Modificada | Media (6.3) | 0.18% | — | Qualys Cloud Agent | 18/4/2023 | 17/6/2026 | An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack vector. This allows attackers to assume the privileges of the process, and they may delete or otherwise on unauthorized files, allowing for… | |
| Modificada | Alta (7) | 0.22% | — | Qualys Cloud Agent | 18/4/2023 | 17/6/2026 | An Executable Hijacking condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers may load a malicious copy of a Dependency Link Library (DLL) via a local attack vector instead of the DLL that the application was expecting, when processes are running with escalated… | |
| Modificada | Crítica (9.8) | 0.75% | — | SAP Diagnostics Agent | 11/4/2023 | 17/6/2026 | Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality,… | |
| Modificada | Alta (8.1) | 14% | — | SAP Diagnostics Agent | 11/4/2023 | 17/6/2026 | Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality,… | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Trusted Device Agent | 6/4/2023 | 17/6/2026 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | |
| Modificada | Media (6.5) | 0.64% | — | Trellix Agent | 3/4/2023 | 17/6/2026 | A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable. |