Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.65% | — | Budibase | 6/4/2023 | 17/6/2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. Versions prior to 2.4.3 (07 March 2023) are vulnerable to Server-Side Request Forgery. This can lead to an attacker gaining access to a Budibase AWS secret key. Users of Budibase cloud need to take no action. Self-host users who… | |
| Modificada | Crítica (9.8) | 0.83% | — | Jenkins Role-based Authorization Strategy | 2/4/2023 | 17/6/2026 | Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled. | |
| Modificada | Crítica (9.8) | 1.1% | — | Basercms | 23/3/2023 | 17/6/2026 | baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch. | |
| Modificada | Crítica (9.8) | 1.5% | — | Basercms | 23/3/2023 | 17/6/2026 | baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch. | |
| Modificada | Media (5.3) | 0.63% | — | Couchbase Server | 23/3/2023 | 17/6/2026 | In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. | |
| Modificada | Media (5.5) | 4.1% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 1.8% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 1.8% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Alta (7.5) | 0.25% | — | WP CSV TO Database Project WP CSV TO Database | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions. | |
| Modificada | Media (4.3) | 0.23% | — | Xnau Participants Database | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update. | |
| Modificada | Alta (7.1) | 0.61% | 💥 PoC | Linux KernelNetapp HCI Baseboard Management Controller | 26/2/2023 | 17/6/2026 | In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. | |
| Modificada | Media (4.9) | 0.51% | — | Intel Baseboard Management Controller Firmware | 16/2/2023 | 17/6/2026 | Uncaught exception in webserver for the Integrated BMC in some Intel(R) platforms before versions 2.86, 2.09 and 2.78 may allow a privileged user to potentially enable denial of service via network access. | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Sling JCR Base | 14/2/2023 | 17/6/2026 | Apache Sling JCR Base < 3.1.12 has a critical injection vulnerability when running on old JDK versions (JDK 1.8.191 or earlier) through utility functions in RepositoryAccessor. The functions getRepository and getRepositoryFromURL allow an application to access data stored in a remote location via JDNI and RMI. Users… | |
| Modificada | Alta (7.5) | 0.45% | — | Couchbase Server | 6/2/2023 | 17/6/2026 | Couchbase Server anterior a 6.6.6, 7.x anterior a 7.0.5 y 7.1.x anterior a 7.1.2 exponen información confidencial a un actor no autorizado. | |
| Modificada | Alta (8.1) | 0.66% | — | Couchbase Server | 6/2/2023 | 17/6/2026 | An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using… | |
| Modificada | Media (4.9) | 0.96% | — | Couchbase Server | 6/2/2023 | 17/6/2026 | An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service. | |
| Modificada | Media (6.3) | 0.38% | — | Metabase | 28/1/2023 | 17/6/2026 | Metabase es una plataforma de análisis de datos de código abierto. Las versiones afectadas están sujetas a una gestión de privilegios inadecuada. Según lo previsto, los destinatarios de las suscripciones a paneles pueden ver los datos tal como los ve el creador de esa suscripción. Esto permite que alguien con mayor… | |
| Modificada | Media (4.1) | 0.44% | — | Metabase | 28/1/2023 | 17/6/2026 | Metabase es una plataforma de análisis de datos de código abierto. Las versiones afectadas están sujetas a la exposición de información confidencial a un actor no autorizado. Los usuarios del espacio aislado no deberían poder ver datos sobre otros usuarios de Metabase en ninguna parte de la aplicación Metabase. Sin… | |
| Modificada | Alta (7.5) | 0.42% | — | Solarwinds Database Performance Analyzer | 20/1/2023 | 17/6/2026 | En DPA 2022.4 y versiones anteriores, los volcados de memoria del montón generados contienen información sensible en texto no cifrado. | |
| Modificada | Media (5.4) | 0.40% | — | Solarwinds Database Performance Analyzer | 20/1/2023 | 17/6/2026 | En Database Performance Analyzer (DPA) 2022.4 y versiones anteriores, ciertos vectores de URL son susceptibles a cross-site scripting reflejado autenticado. | |
| Modificada | Alta (7.5) | 0.59% | — | Oracle Database Server | 18/1/2023 | 17/6/2026 | Vulnerabilidad en el componente Oracle Data Provider para .NET de Oracle Database Server. Las versiones compatibles que se ven afectadas son 19c y 21c. Una vulnerabilidad difícil de explotar permite que un atacante no autenticado con acceso a la red a través de TCPS comprometa el proveedor de datos de Oracle para… | |
| Modificada | Media (6.3) | 0.45% | — | Oracle Database | 18/1/2023 | 17/6/2026 | Vulnerabilidad en el componente de seguridad RDBMS de Oracle Database de Oracle Database Server. Las versiones compatibles que se ven afectadas son 19c y 21c. Una vulnerabilidad fácilmente explotable permite que un atacante con privilegios bajos y privilegios de Crear sesión con acceso a la red a través de Oracle Net… |