Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
2678 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.89% | — | Underscore-keypath Project Underscore-keypath | 1/8/2023 | 17/6/2026 | Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”. | |
| Modificada | Crítica (9.8) | 1.2% | — | Oscore | 28/7/2023 | 17/6/2026 | Se ha descubierto que Oscore v2.2.6 e inferiores contienen una vulnerabilidad de inyección de código en el componente "com.opensymphony.util.EJBUtils.createStateless". Esta vulnerabilidad se aprovecha pasando un argumento no comprobado. | |
| Modificada | Media (6.1) | 0.55% | — | Pimcore | 21/7/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4. | |
| Modificada | Media (5.4) | 0.57% | — | Pimcore | 21/7/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.6.4. | |
| Modificada | Alta (7.2) | 1.2% | — | Pimcore | 21/7/2023 | 17/6/2026 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.6.4. | |
| Modificada | Media (6.5) | 0.66% | — | Pimcore | 21/7/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4. | |
| Modificada | Alta (7.5) | 1.2% | — | Artbees Jupiter X Core | 21/7/2023 | 17/6/2026 | El plugin Jupiter X Core para WordPress es vulnerable a la descarga de archivos arbitrarios en versiones hasta la 2.5.0 inclusive. Esto hace posible que atacantes no autenticados descarguen el contenido de archivos arbitrarios en el servidor, que pueden contener información sensible. Se requiere la versión premium del… | |
| Modificada | Media (5.5) | 0.84% | — | Microsoft Chakracore | 18/7/2023 | 17/6/2026 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp(). | |
| Modificada | Media (5.5) | 0.83% | — | Microsoft Chakracore | 18/7/2023 | 17/6/2026 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). | |
| Modificada | Media (5.5) | 0.83% | — | Microsoft Chakracore | 18/7/2023 | 17/6/2026 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). | |
| Modificada | Media (5.5) | 0.83% | — | Microsoft Chakracore | 18/7/2023 | 17/6/2026 | ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). | |
| Modificada | Media (5.5) | 0.86% | — | Microsoft Chakracore | 18/7/2023 | 17/6/2026 | ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray(). | |
| Modificada | Alta (7.6) | 0.43% | — | Taphome Core Firmware | 17/7/2023 | 17/6/2026 | An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access… | |
| Modificada | Alta (8.8) | 0.56% | — | Taphome Core Firmware | 17/7/2023 | 17/6/2026 | A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may gain full access to the device by using this vulnerability. | |
| Modificada | Alta (7.2) | 0.89% | — | Pimcore | 14/7/2023 | 17/6/2026 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.24. | |
| Modificada | Crítica (9.8) | 0.75% | — | Owasp Coreruleset | 13/7/2023 | 17/6/2026 | coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF with a crafted payload, aka "Content-Type confusion" between the WAF and the backend application. This occurs when the web application… | |
| Modificada | Crítica (9.8) | 1.7% | — | Syncfusion EJ2 Aspcore File Provider | 12/7/2023 | 17/6/2026 | The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server. | |
| Modificada | Media (6.1) | 0.58% | — | Pimcore Admin Classic Bundle | 11/7/2023 | 17/6/2026 | Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of privilege, causing the application to execute arbitrary scripts/HTML content. This vulnerability has been… | |
| Modificada | Alta (7.3) | 0.38% | — | SAP S4core | 11/7/2023 | 17/6/2026 | When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted,… | |
| Modificada | Media (6.5) | 0.54% | — | Pimcore Customer Management Framework | 10/7/2023 | 17/6/2026 | Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1. | |
| Modificada | Alta (7.5) | 0.57% | — | Bitcoin Core | 7/7/2023 | 17/6/2026 | Los problemas de gestión de memoria y protección en Bitcoin Core v22 permiten a los atacantes modificar la dirección de envío almacenada en la memoria de la aplicación, lo que potencialmente les permite redirigir las transacciones de Bitcoin a los monederos de su elección. | |
| Modificada | Alta (7.5) | 0.72% | — | Zope Products.cmfcore | 3/7/2023 | 17/6/2026 | Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's marshal module to handle unchecked input in a public method on `PortalFolder` objects can lead to an unauthenticated denial of service and crash situation. The code in question is exposed by all portal… | |
| Modificada | Alta (8) | 0.48% | — | ABB Txpert HUB Coretec 4 Firmware | 28/6/2023 | 17/6/2026 | A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to ADMIN. To exploit the vulnerability the attacker can inject shell commands through a particular field of the web user interface that will be… | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 17/6/2023 | 17/6/2026 | Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | |
| Modificada | Alta (7.8) | 0.16% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 14/6/2023 | 17/6/2026 | A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver. |