Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
130 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Combodo Itop | 9/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page. | |
| Modificada | Media (6.1) | 0.68% | — | Combodo Itop | 25/10/2023 | 17/6/2026 | iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0. | |
| Modificada | Media (6.1) | 0.52% | 💥 PoC | Combodo Itop | 25/10/2023 | 17/6/2026 | iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.5) | 0.96% | — | Weave Gitops Terraform Controller | 14/7/2023 | 17/6/2026 | Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave GitOps Terraform Controller which could allow an authenticated remote attacker to view sensitive information. This vulnerability stems from… | |
| Modificada | Crítica (9.8) | 0.91% | — | Combodo Itop | 14/3/2023 | 17/6/2026 | Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1. | |
| Modificada | Alta (7.5) | 26% | — | Combodo Itop | 14/3/2023 | 17/6/2026 | Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user who can log in on iTop is able to take over any account just by knowing the account's username. This issue is fixed in versions 2.7.8 and 3.0.2-1. | |
| Modificada | Media (6) | 0.24% | — | Weave Gitops | 9/1/2023 | 17/6/2026 | Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied against a Kubernetes cluster. The communication between GitOps Run and the local S3… | |
| Modificada | Alta (7.8) | 0.32% | — | Weave Gitops | 9/1/2023 | 17/6/2026 | Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3 bucket which it uses for synchronizing… | |
| Modificada | Media (5.4) | 0.82% | — | Weave.works Gitops | 1/9/2022 | 17/6/2026 | Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in Weave GitOps Enterprise UI via a GitopsCluster dashboard link. An… | |
| Modificada | Crítica (9.8) | 0.51% | — | Weave Gitops Tools | 18/8/2022 | 17/6/2026 | The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to arbitrary code execution on behalf of the user running VSCode. Users relying on kubeconfigs that are generated or altered by other processes or users are affected by… | |
| Modificada | Crítica (9.8) | 1.3% | — | Weave Gitops Tools | 18/8/2022 | 17/6/2026 | The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the extension, in the context of the user that is running VSCode. Users using the VSCode extension to manage clusters that are shared amongst other… | |
| Modificada | Media (5.4) | 0.58% | — | Iobit Itop VPN | 6/7/2022 | 9/7/2026 | The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing ImpersonateNamedPipeClient(). | |
| Modificada | Media (6.6) | 0.71% | — | Iobit Advanced System CareIobit Driver BoosterIobit Itop Screen RecorderIobit Itop Screenshot+1 | 6/7/2022 | 9/7/2026 | IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install… | |
| Modificada | Alta (7.5) | 1.2% | — | Weave Gitops | 27/6/2022 | 17/6/2026 | Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka KubeConfg, of registered Kubernetes… | |
| Modificada | Media (6.1) | 1.8% | 💥 PoC | Combodo Itop | 14/6/2022 | 17/6/2026 | ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php. | |
| Modificada | Media (6.1) | 2.3% | 💥 PoC | Combodo Itop | 10/6/2022 | 17/6/2026 | ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php. | |
| Modificada | Media (5.4) | 0.93% | — | Combodo Itop | 21/4/2022 | 17/6/2026 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system. Users are advised to upgrade. There are no… | |
| Modificada | Media (6.1) | 0.66% | — | Combodo Itop | 21/4/2022 | 17/6/2026 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross site scripting attack vector. Users are advised to upgrade. There are no known workarounds for this… | |
| Modificada | Media (6.1) | 0.66% | — | Combodo Itop | 21/4/2022 | 17/6/2026 | Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files. Users are advised to upgrade. There are no known workarounds for this issue. | |
| Modificada | Media (5.4) | 0.75% | — | Combodo Itop | 5/4/2022 | 17/6/2026 | Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possible for scripts outside of script tags when displaying HTML attachments. This issue is fixed in versions 2.7.6 and 3.0.0. There are currently no known workarounds. | |
| Modificada | Alta (8.8) | 5.7% | 💥 PoC | Combodo Itop | 5/4/2022 | 17/6/2026 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on the server using http server user privileges. This issue is fixed in versions 2.7.6 and 3.0.0.… | |
| Modificada | Alta (8.1) | 0.70% | — | Combodo Itop | 5/4/2022 | 17/6/2026 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file. | |
| Modificada | Media (6.5) | 1.4% | — | Opcfoundation Ua-nodesetSiemens Simatic NET PCSiemens Sitop ManagerSiemens Telecontrol Server Basic | 21/3/2022 | 17/6/2026 | The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference. | |
| Modificada | Media (6.5) | 0.76% | — | Argoproj Argo CDRedhat Openshift Gitops | 16/2/2022 | 17/6/2026 | A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this… |