Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1904 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.17% | — | Trellix Agent | 3/4/2023 | 17/6/2026 | A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions. | |
| Modificada | Media (5.5) | 0.22% | — | F5 Nginx AgentF5 Nginx Instance Manager | 29/3/2023 | 17/6/2026 | Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace… | |
| Modificada | Media (4.4) | 0.29% | — | Cynet Client Agent | 28/3/2023 | 17/6/2026 | Cynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable the EDR functions by disabling process privilege tokens. | |
| Modificada | Media (4.3) | 0.56% | — | Adobe CommerceAdobe Magento Open Source | 27/3/2023 | 17/6/2026 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure. | |
| Modificada | Media (5.3) | 0.96% | — | Adobe CommerceAdobe Magento Open Source | 27/3/2023 | 17/6/2026 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not… | |
| Modificada | Media (4.8) | 58% | — | Adobe CommerceAdobe Magento Open Source | 27/3/2023 | 17/6/2026 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they… | |
| Modificada | Alta (7.5) | 0.93% | — | Adobe CommerceAdobe Magento Open Source | 27/3/2023 | 17/6/2026 | Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An unauthenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not… | |
| Modificada | Alta (7.2) | 0.55% | — | SAP Host Agent | 14/3/2023 | 17/6/2026 | SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request which results in a memory corruption error. This error can be used to reveal but not modify any technical information about the server. It can… | |
| Modificada | Alta (8.8) | 0.99% | — | Agentejo Cockpit | 10/3/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. | |
| Modificada | Crítica (9.8) | 0.86% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22336 vulnerabilities together,… | |
| Modificada | Crítica (9.8) | 1.1% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22344 vulnerabilities together, it may… | |
| Modificada | Alta (7.5) | 0.74% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to bypass access restriction and download an arbitrary file of the directory where the product runs. As a result of exploiting this vulnerability with CVE-2023-22336 and… | |
| Modificada | Media (5.5) | 0.35% | — | Agentejo Cockpit | 3/3/2023 | 17/6/2026 | Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0. | |
| Modificada | Crítica (9.8) | 0.97% | — | Forgerock Java Policy Agents | 28/2/2023 | 17/6/2026 | Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1 | |
| Modificada | Crítica (9.8) | 0.97% | — | Forgerock WEB Policy Agents | 28/2/2023 | 17/6/2026 | Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1 | |
| Modificada | Media (6.1) | 0.71% | — | Agentejo Cockpit | 21/2/2023 | 17/6/2026 | Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Alta (8.8) | 0.18% | — | SAP Host Agent | 14/2/2023 | 17/6/2026 | An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or… | |
| Modificada | Alta (7.8) | 0.15% | — | Acronis AgentAcronis Cyber ProtectAcronis Cyber Protect Home Office | 13/2/2023 | 17/6/2026 | Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107, Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984. | |
| Modificada | Alta (7.5) | 0.25% | — | Acronis AgentAcronis Cyber Protect | 13/2/2023 | 17/6/2026 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161, Acronis Cyber Protect 15 (Windows) before build 30984. | |
| Modificada | Media (5.4) | 0.37% | — | Agentejo Cockpit | 11/2/2023 | 17/6/2026 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev. | |
| Modificada | Alta (8.8) | 0.34% | — | Agentejo Cockpit | 9/2/2023 | 17/6/2026 | Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. | |
| Modificada | Alta (7.8) | 0.29% | — | Paloaltonetworks Cortex XDR Agent | 8/2/2023 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent. | |
| Modificada | Media (6.7) | 0.21% | — | Paloaltonetworks Cortex XDR Agent | 8/2/2023 | 17/6/2026 | An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent. | |
| Modificada | Alta (7.5) | 0.99% | — | Openmage Magento | 28/1/2023 | 17/6/2026 | OpenMage LTS es una plataforma de comercio electrónico. Las versiones anteriores a 19.4.22 y 20.0.19 contienen un bucle infinito en el filtro de código malicioso en determinadas condiciones. Las versiones 19.4.22 y 20.0.19 tienen una solución para este problema. No se conocen workarounds. |