Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 98% | 💥 Exploit | Zohocorp Manageengine Admanager Plus | 13/4/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. | |
| Modificada | Alta (7.4) | 0.26% | — | Siemens Scalance X200-4p IRT FirmwareSiemens Scalance X201-3p IRT FirmwareSiemens Scalance X201-3p IRT PRO FirmwareSiemens Scalance X202-2irt Firmware+9 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2),… | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.72% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Media (4.8) | 32% | 💥 PoC | Updraftplus All-in-one Security | 10/4/2023 | 17/6/2026 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this… | |
| Modificada | Media (4.9) | 20% | 💥 PoC | Updraftplus All-in-one Security | 10/4/2023 | 17/6/2026 | The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings pages, allowing an authorized user (admin+) to view the contents of arbitrary files and list directories anywhere on the server (to which the web server has access). The plugin only displays the last… | |
| Modificada | Alta (7.5) | 78% | — | Zohocorp Manageengine Adselfservice Plus | 5/4/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. | |
| Modificada | Crítica (9.8) | 1.5% | — | Sato-global Cl4nx Plus Firmware | 31/3/2023 | 17/6/2026 | An authentication bypass vulnerability in the web client interface for the CL4NX printer before firmware version 1.13.3-u724_r2 provides remote unauthenticated attackers with access to execute commands intended only for valid/authenticated users, such as file uploads and configuration changes. | |
| Modificada | Media (5.4) | 20% | — | Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager PlusZohocorp Manageengine Opmanager MSP | 30/3/2023 | 17/6/2026 | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.41% | — | Cpplusworld Kvms PRO | 28/3/2023 | 17/6/2026 | CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected. | |
| Modificada | Alta (8.8) | 0.73% | — | Xxyopen Novel-plus | 23/3/2023 | 17/6/2026 | Se encontró una vulnerabilidad en novel-plus 3.6.2. Se ha clasificado como crítico. Esto afecta a una parte desconocida del archivo /common/sysFile/list. La manipulación del argumento sort conduce a la inyección sql. Es posible iniciar el ataque de forma remota. El exploit ha sido divulgado al público y puede ser… | |
| Modificada | Crítica (9.1) | 3.1% | — | Zohocorp Manageengine Adselfservice Plus | 23/3/2023 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications. | |
| Modificada | Crítica (9.8) | 0.89% | — | Xxyopen Novel-plus | 23/3/2023 | 17/6/2026 | Se encontró una vulnerabilidad en novel-plus 3.6.2 y se clasificó como crítica. Este problema afecta a algunas funciones desconocidas del archivo DictController.java. La manipulación del argumento orderby conduce a la inyección sql. El ataque puede ser lanzado de forma remota. El exploit ha sido divulgado al público y… | |
| Modificada | Alta (7.2) | 0.87% | — | Xxyopen Novel-plus | 23/3/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en novel-plus 3.6.2 y se ha clasificado como crítica. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo common/log/list. La manipulación del argumento sort conduce a la inyección sql. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al… | |
| Modificada | Crítica (9.8) | 1.0% | — | Xxyopen Novel-plus | 23/3/2023 | 17/6/2026 | Una vulnerabilidad, que se clasificó como crítica, se encontró en novel-plus 3.6.2. Afectando la función MenuService del archivo sys/menu/list. La manipulación del argumento sort conduce a la inyección sql. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede ser utilizado.… | |
| Modificada | Crítica (9.8) | 9.8% | 💥 Exploit | Netgate Pfsense PlusPfsense | 22/3/2023 | 17/6/2026 | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests. | |
| Modificada | Media (4.8) | 0.37% | — | Plustime Service Area Postcode Checker | 20/3/2023 | 17/6/2026 | Auth. (admin+) vulnerability in Second2none Service Area Postcode Checker plugin <= 2.0.8 versions. | |
| Modificada | Media (5.5) | 0.32% | — | Maxpcsecure Anti Virus Plus | 18/3/2023 | 17/6/2026 | A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been rated as problematic. This issue affects the function 0x220019 in the library MaxProctetor64.sys of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The… | |
| Modificada | Media (5.5) | 0.32% | — | Maxpcsecure Anti Virus Plus | 18/3/2023 | 17/6/2026 | A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been declared as problematic. This vulnerability affects the function 0x220019 in the library MaxProc64.sys of the component IoControlCode Handler. The manipulation of the argument SystemBuffer leads to denial of service. Attacking locally is a… | |
| Modificada | Media (5.5) | 0.30% | — | Maxpcsecure Anti Virus Plus | 18/3/2023 | 17/6/2026 | A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been classified as critical. This affects the function 0x220020 in the library MaxCryptMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The… | |
| Modificada | Media (5.5) | 0.30% | — | Maxpcsecure Anti Virus Plus | 18/3/2023 | 17/6/2026 | A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. Affected by this issue is the function 0x220020 in the library SDActMon.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. An attack has to be approached locally. The exploit has… | |
| Modificada | Media (4.6) | 0.29% | — | Dell Inspiron 14 Plus 7420 FirmwareDell Inspiron 14 Plus 7620 FirmwareDell Inspiron 3511 FirmwareDell Inspiron 3520 Firmware+71 | 8/3/2023 | 17/6/2026 | Dell BIOS contains an Improper Authorization vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (6.5) | 0.80% | — | Posimyth THE Plus Addons FOR Elementor | 7/3/2023 | 17/6/2026 | The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used… | |
| Modificada | Alta (8.8) | 0.89% | — | Posimyth THE Plus Addons FOR Elementor | 7/3/2023 | 17/6/2026 | The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the default… |