Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
3716 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.90% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and… | |
| Modificada | Crítica (9.8) | 1.4% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication. | |
| Modificada | Crítica (9.8) | 34% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption. | |
| Modificada | Crítica (9.8) | 1.2% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server. | |
| Modificada | Crítica (9.8) | 1.8% | — | Vmware Vcenter Server | 22/6/2023 | 17/6/2026 | The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts… | |
| Modificada | Media (4.8) | 0.45% | — | Gbcom LAC WEB Control Center | 22/6/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device. | |
| Modificada | Media (6.1) | 0.39% | — | Subnet Powersystem Center | 19/6/2023 | 17/6/2026 | SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications. | |
| Modificada | Crítica (9.1) | 0.58% | — | Subnet Powersystem Center | 19/6/2023 | 17/6/2026 | SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-of-service condition or a loss of data integrity. | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Jt2goSiemens Teamcenter Visualization | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),… | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Jt2goSiemens Teamcenter Visualization | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),… | |
| Modificada | Media (5.5) | 0.19% | — | Siemens Jt2goSiemens Teamcenter Visualization | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),… | |
| Modificada | Media (5.5) | 0.18% | — | Siemens Jt2goSiemens Teamcenter Visualization | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),… | |
| Modificada | Media (5.3) | 0.62% | — | Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie FirmwarePhoenixcontact FL Mguard 4302 Firmware+22 | 13/6/2023 | 17/6/2026 | Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks. | |
| Modificada | Alta (7.8) | 0.26% | — | Siemens Jt2goSiemens Teamcenter Visualization | 7/6/2023 | 17/6/2026 | Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process. | |
| Modificada | Alta (7.5) | 0.46% | — | Asustor Download Center | 31/5/2023 | 17/6/2026 | Download Center no valida correctamente la ruta de archivo enviada por un usuario. Un atacante puede aprovechar esta vulnerabilidad para obtener acceso no autorizado a archivos o directorios confidenciales sin las restricciones de permisos adecuadas. Download Center se ve afectado en ADM 4.0 y en versiones superiores.… | |
| Modificada | Media (6.1) | 0.47% | — | Broadcom Vmware Nsx-t Data Center | 26/5/2023 | 17/6/2026 | NSX-T contiene una vulnerabilidad de cross-site scripting reflejado debido a la falta de validación de entrada. Un atacante remoto puede inyectar HTML o JavaScript para redirigir a páginas maliciosas. | |
| Modificada | Alta (7.1) | 0.30% | — | Opentext Archive Center Administration | 24/5/2023 | 17/6/2026 | The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft… | |
| Modificada | Media (6.1) | 0.38% | — | Hitachi OPS Center Analyzer | 23/5/2023 | 17/6/2026 | Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) allows Reflected XSS.This issue affects Hitachi Ops Center Analyzer: from 10.9.1-00 before 10.9.2-00. | |
| Modificada | Media (4.3) | 0.48% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas… | |
| Modificada | Media (4.3) | 0.49% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas… | |
| Modificada | Alta (8.8) | 0.62% | — | Cisco Catalyst Center | 18/5/2023 | 17/6/2026 | Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas… | |
| Modificada | Crítica (9.8) | 0.88% | — | Oretnom23 Student Study Center Desk Management System | 18/5/2023 | 17/6/2026 | Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability. | |
| Modificada | Crítica (9.8) | 0.96% | — | Netapp Snapcenter | 12/5/2023 | 17/6/2026 | SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.55% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access. |