Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
3843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 2/8/2023 | 17/6/2026 | Existe una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en una página no revelada de la utilidad de configuración de BIG-IP que permite a un atacante ejecutar JavaScript en el contexto del usuario actualmente conectado. Nota: No se evalúan las versiones de software que han alcanzado el fin del soporte ténico… | |
| Modificada | Media (5.3) | 0.70% | — | IBM Tririga Application Platform | 31/7/2023 | 17/6/2026 | IBM TRIRIGA v3.0, v4.0 y v4.4 podrían permitir a un atacante remoto obtener información sensible cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría utilizarse en ataques posteriores contra el sistema. ID de IBM X-Force: 190744. | |
| Modificada | Media (6.5) | 0.64% | — | Vmware Isolation SegmentVmware Tanzu Application Service FOR Virtual Machines | 26/7/2023 | 17/6/2026 | The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials… | |
| Modificada | Media (5.5) | 0.21% | — | MOJ Applicant Programme | 25/7/2023 | 17/6/2026 | Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker. | |
| Modificada | Media (6.5) | 0.73% | — | Netentsec Application Security Gateway | 20/7/2023 | 17/6/2026 | A vulnerability was found in Beijing Netcon NS-ASG 6.3. It has been classified as problematic. This affects an unknown part of the file /admin/test_status.php. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is… | |
| Modificada | Alta (8) | 1.3% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Privilege Escalation to root administrator (nsroot) | |
| Modificada | Media (6.1) | 2.6% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 5/8/2026 | Unauthenticated remote code execution | |
| Modificada | Media (6.1) | 0.42% | — | Oracle Applications Framework | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.3-12.3.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful… | |
| Modificada | Media (6.5) | 0.35% | — | Oracle WEB Applications Desktop Integrator | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: MS Excel Specific). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications… | |
| Modificada | Media (6.5) | 0.58% | — | Oracle Health Sciences Applications | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Health Sciences Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Blinding Functionality). Supported versions that are affected are 3.1.0.2, 3.1.1.3 and 3.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access… | |
| Modificada | Media (5.6) | 0.38% | — | Oracle Application Express | 18/7/2023 | 17/6/2026 | Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Application Express Administration: 18.2-22.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Crítica (9) | 0.61% | — | Oracle Application Express | 18/7/2023 | 17/6/2026 | Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Crítica (9) | 0.61% | — | Oracle Application Express | 18/7/2023 | 17/6/2026 | Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Alta (7.4) | 0.39% | — | SAP Netweaver Application Server Abap | 11/7/2023 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper… | |
| Modificada | Media (5.3) | 0.45% | — | SAP Netweaver Application Server FOR Java | 11/7/2023 | 17/6/2026 | SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interaction. There is no ability to view any information or any effect on availability. | |
| Modificada | Media (6.1) | 81% | 💥 Exploit | Citrix GatewayCitrix Application Delivery Controller | 10/7/2023 | 17/6/2026 | Los productos ADC y Gateway de Citrix son vulnerables a ataques de tipo Cross-Site Scripting (XSS). | |
| Modificada | Alta (7.5) | 1.1% | — | Citrix Application Delivery ControllerCitrix Gateway | 10/7/2023 | 17/6/2026 | Arbitrary file read in Citrix ADC and Citrix Gateway | |
| Modificada | Media (4.8) | 0.33% | — | UI Unifi Network Application | 8/7/2023 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit a malicious web page. | |
| Modificada | Media (5.5) | 0.12% | — | IBM Websphere Application Server | 7/7/2023 | 17/6/2026 | IBM WebSphere Application Server v8.5 y v9.0 podrían proporcionar una seguridad más débil de lo esperado, causada por la codificación incorrecta en un archivo de configuración local. ID de IBM X-Force: 258637. | |
| Analizada | Crítica (9.1) | 0.76% | — | UI Unifi Network Application | 1/7/2023 | 17/6/2026 | A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored. | |
| Modificada | Crítica (9.8) | 1.1% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagParseAndStoreData integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 1.1% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagVerifyProvisioning integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow. |