Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 0.78% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system user. This was limited to specific… | |
| Modificada | Media (4.3) | 1.1% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted POP3 server response to reasonable… | |
| Modificada | Media (4.3) | 1.1% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted IMAP server response to reasonable… | |
| Modificada | Media (4.3) | 1.1% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted SMTP server response to reasonable… | |
| Modificada | Media (4.3) | 0.84% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight about topology and running services. We… | |
| Modificada | Media (5.3) | 0.79% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are… | |
| Modificada | Media (6.5) | 0.98% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not explicitly shared with other users. No… | |
| Modificada | Baja (3.3) | 0.33% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known. | |
| Modificada | Media (6.1) | 0.56% | — | Kau-boys Backend Localization | 24/4/2023 | 16/6/2026 | A vulnerability classified as problematic has been found in Kau-Boy Backend Localization Plugin 2.0 on WordPress. Affected is the function backend_localization_admin_settings/backend_localization_save_setting/backend_localization_login_form/localize_backend of the file backend_localization.php. The manipulation leads… | |
| Modificada | Media (6.1) | 0.56% | — | Kau-boys Backend Localization | 24/4/2023 | 16/6/2026 | A vulnerability was found in Kau-Boy Backend Localization Plugin up to 1.6.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the file backend_localization.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.0 is… | |
| Analizada | Crítica (9.8) | 1.5% | — | Apache Kerby Ldap Backend | 20/2/2023 | 17/6/2026 | An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. | |
| Modificada | Media (5.4) | 0.45% | — | Linuxfoundation Backstage Catalog-modelLinuxfoundation Backstage Core-componentsLinuxfoundation Backstage Plugin-catalog-backend | 14/2/2023 | 17/6/2026 | Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior to 0.12.4, and `@backstage/plugin-catalog-backend` prior to 1.7.2 are affected by a cross-site scripting vulnerability. This vulnerability allows a malicious actor with… | |
| Modificada | Media (4.3) | 0.46% | — | Nextcloud Openid Connect User Backend | 25/11/2022 | 17/6/2026 | user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor with access to monitor user traffic may have been able to compromise account security. This issue… | |
| Modificada | Media (5.4) | 0.63% | — | Nextcloud Openid Connect User Backend | 25/11/2022 | 17/6/2026 | user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on this endpoint. Additionally this vulnerability has only been… | |
| Modificada | Crítica (9.3) | 1.2% | — | Sphere Imagebackend Project Sphere Imagebackend | 11/7/2022 | 17/6/2026 | The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (6.1) | 0.68% | — | Linuxfoundation Auth Backend | 26/11/2021 | 17/6/2026 | Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate access tokens or other secrets from the… | |
| Modificada | Media (5.3) | 1.7% | — | Radarcovid Radar-covid-backend-dp3t-serverRadarcovid | 13/11/2020 | 17/6/2026 | Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identification and de-anonymization of COVID-19 positive users that upload Radar COVID TEKs to the Radar COVID server is possible. This vulnerability enables the identification and de-anonymization of… | |
| Modificada | Alta (7.5) | 1.4% | — | Dp3t-backend-software Development KIT Project Dp3t-backend-software Development KIT | 30/7/2020 | 17/6/2026 | An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the signature check by providing a JWT token with alg=none. | |
| Modificada | Media (5.7) | 1.0% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079. | |
| Modificada | Alta (8) | 1.5% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. | |
| Modificada | Media (4.3) | 1.2% | — | Sane-project Sane BackendsOpensuse LeapCanonical Ubuntu Linux | 24/6/2020 | 17/6/2026 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081. | |
| Modificada | Media (4.3) | 1.0% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083. | |
| Modificada | Media (4.3) | 1.1% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082. | |
| Modificada | Alta (8.8) | 3.0% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080. | |
| Modificada | Media (5.5) | 0.50% | — | Sane-project Sane BackendsFedoraproject FedoraDebian LinuxOpensuse Leap+1 | 1/6/2020 | 17/6/2026 | A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075. |