Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
3817 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Alta (7.4) | 0.39% | — | SAP Netweaver Application Server Abap | 11/7/2023 | 17/6/2026 | SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper… | |
| Modificada | Media (5.3) | 0.45% | — | SAP Netweaver Application Server FOR Java | 11/7/2023 | 17/6/2026 | SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interaction. There is no ability to view any information or any effect on availability. | |
| Modificada | Media (6.1) | 81% | 💥 Exploit | Citrix GatewayCitrix Application Delivery Controller | 10/7/2023 | 17/6/2026 | Los productos ADC y Gateway de Citrix son vulnerables a ataques de tipo Cross-Site Scripting (XSS). | |
| Modificada | Alta (7.5) | 1.1% | — | Citrix Application Delivery ControllerCitrix Gateway | 10/7/2023 | 17/6/2026 | Arbitrary file read in Citrix ADC and Citrix Gateway | |
| Modificada | Media (4.8) | 0.33% | — | UI Unifi Network Application | 8/7/2023 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit a malicious web page. | |
| Modificada | Media (5.5) | 0.12% | — | IBM Websphere Application Server | 7/7/2023 | 17/6/2026 | IBM WebSphere Application Server v8.5 y v9.0 podrían proporcionar una seguridad más débil de lo esperado, causada por la codificación incorrecta en un archivo de configuración local. ID de IBM X-Force: 258637. | |
| Analizada | Crítica (9.1) | 0.76% | — | UI Unifi Network Application | 1/7/2023 | 17/6/2026 | A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored. | |
| Modificada | Crítica (9.8) | 1.1% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagParseAndStoreData integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 1.1% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagVerifyProvisioning integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys prefix_len+feature_name_len integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys file_name_len integer overflow and resultant buffer overflow. | |
| Modificada | Crítica (9.8) | 0.93% | — | Widevine Trusted Application | 26/6/2023 | 17/6/2026 | Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys feature_name_len integer overflow and resultant buffer overflow. | |
| Modificada | Media (5.3) | 0.64% | — | IBM Maximo Application SuiteIBM Maximo Asset Management | 5/6/2023 | 17/6/2026 | IBM Maximo Asset Management v7.6.1.2, v7.6.1.3 e IBM Maximo Application Suite v8.8.0 almacenan información confidencial en parámetros de URL. Esto puede dar lugar a la divulgación de información si partes no autorizadas tienen acceso a las URL a través de los registros del servidor, el encabezado de referencia o el… | |
| Modificada | Media (5.9) | 0.34% | — | IBM Maximo Application Suite | 5/6/2023 | 17/6/2026 | IBM Maximo Application Suite - Manage Component v8.8.0 y v8.9.0 transmite información confidencial en texto claro que podría ser interceptada por un atacante mediante técnicas de "man in the middle". IBM X-Force ID: 249208. | |
| Modificada | Alta (8.8) | 0.60% | — | Mobatime WEB Application | 2/6/2023 | 17/6/2026 | Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation, Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobatime web application: through 06.7.22. | |
| Modificada | Alta (8.8) | 0.82% | — | Mobatime WEB Application | 2/6/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user to Upload a Web Shell to a Web Server.This issue affects Mobatime web application: through 06.7.22. | |
| Modificada | Crítica (9.1) | 0.86% | — | IBM Websphere Application Server | 11/5/2023 | 17/6/2026 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249185. | |
| Modificada | Crítica (9.1) | 0.62% | — | SAP Netweaver Application Server FOR Java | 9/5/2023 | 17/6/2026 | In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication. A… | |
| Modificada | Alta (7.5) | 0.56% | — | Netentsec Application Security Gateway | 5/5/2023 | 9/7/2026 | Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information. | |
| Modificada | Crítica (9.8) | 0.63% | — | Netentsec Application Security Gateway | 5/5/2023 | 9/7/2026 | NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php. | |
| Modificada | Media (5.3) | 0.36% | — | IBM Websphere Application Server | 3/5/2023 | 17/6/2026 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server, could allow an authenticated user to conduct spoofing attacks. A man-in-the-middle attacker could exploit this… | |
| Modificada | Alta (7.5) | 0.62% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (4.3) | 1.2% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which… |