Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
2143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.63% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Linuxone+1 | 7/7/2023 | 17/6/2026 | Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri. | |
| Modificada | Alta (7.8) | 0.30% | — | Osslsigncode Project Osslsigncode | 3/7/2023 | 17/6/2026 | Buffer Overflow vulnerability in mtrojnar osslsigncode v.2.3 and before allows a local attacker to execute arbitrary code via a crafted .exe, .sys, and .dll files. | |
| Modificada | Media (4.8) | 0.50% | — | Etoilewebdesign Ultimate Product Catalog | 27/6/2023 | 17/6/2026 | The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.8) | 0.35% | — | Adobe Substance 3D Designer | 15/6/2023 | 17/6/2026 | Adobe Substance 3D Designer version 12.4.1 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (4.8) | 0.37% | — | Designextreme We're Open! | 13/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Noah Hearle, Design Extreme We’re Open! plugin <= 1.46 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Stpetedesign Call NOW Accessibility Button | 12/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in StPeteDesign Call Now Accessibility Button plugin <= 1.1 versions. | |
| Modificada | Alta (8.8) | 0.56% | — | Coolplugins Process Steps Template Designer | 7/6/2023 | 17/6/2026 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such… | |
| Modificada | Crítica (9.8) | 1.6% | — | Etoilewebdesign Ultimate Reviews | 7/6/2023 | 17/6/2026 | The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. | |
| Modificada | Media (4.6) | 0.70% | — | Xootix Login/signup Popup | 7/6/2023 | 17/6/2026 | The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can… | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Tshirtecommerce Custom Product Designer | 1/6/2023 | 17/6/2026 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without… | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Tshirtecommerce Custom Product Designer | 1/6/2023 | 17/6/2026 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on the system in order to open files… | |
| Modificada | Media (5.3) | 0.54% | — | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using. Users should upgrade to version 3.3.5, which… | |
| Modificada | Media (6.5) | 0.62% | — | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the `/display/map` API route inside the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values in to the… | |
| Modificada | Media (6.5) | 0.62% | — | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.5 in the `nameFilter` function used throughout the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values for… | |
| Modificada | Media (6.5) | 0.63% | — | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `/dataset/data/{id}` API route inside the CMS starting in version 1.4.0 and prior to versions 2.3.17 and 3.3.5. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted… | |
| Modificada | Alta (8.8) | 7.0% | 💥 Exploit | Xibosignage Xibo | 30/5/2023 | 17/6/2026 | Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially crafted zip file can be uploaded to the CMS via the layout import function by an authenticated user which would allow creation of files outside of the CMS library directory as the webserver user. This… | |
| Modificada | Crítica (9.1) | 0.39% | — | Moov Signedxml | 30/5/2023 | 17/6/2026 | En Moov signedxml hasta la versión 1.0.0, el análisis del XML sin procesar (tal y como se recibe) puede dar lugar a resultados diferentes que el análisis del XML procesado y canonicalizado. Por lo tanto, la validación de la firma puede eludirse mediante un ataque de envoltura de firma (también conocido como XSW). | |
| Modificada | Alta (7.5) | 1.1% | — | Signalwire Sofia-sipDebian Linux | 26/5/2023 | 17/6/2026 | Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-flow and integer-overflow in stun_parse_attr_error_code and… | |
| Modificada | Media (6.5) | 0.43% | — | Redhat Build OF QuarkusRedhat Jboss A-mqRedhat KeycloakRedhat Migration Toolkit FOR Runtimes+1 | 26/5/2023 | 17/6/2026 | A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the… | |
| Modificada | Alta (8.8) | 0.26% | — | Orion Woocommerce Products Designer | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ORION Woocommerce Products Designer plugin <= 4.3.3 versions. | |
| Modificada | Media (5.5) | 0.23% | — | Simpledesign Diary With Lock\ | 24/5/2023 | 17/6/2026 | A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the… | |
| Modificada | Crítica (9.8) | 0.76% | — | Cdesigner Project Cdesigner | 17/5/2023 | 17/6/2026 | PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent(). | |
| Modificada | Media (4.3) | 0.43% | — | Jenkins Saml Single Sign-on | 16/5/2023 | 17/6/2026 | A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails. | |
| Modificada | Baja (3.7) | 0.24% | — | Jenkins Saml Single Sign ON | 16/5/2023 | 17/6/2026 | Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections. |