Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
3716 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.80% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 7/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Health Center Patient Record Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 34% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 6/3/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS). | |
| Modificada | Media (6.5) | 6.3% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 6/3/2023 | 17/6/2026 | ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports. | |
| Modificada | Media (6.1) | 0.61% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 5/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file hematology_print.php. The manipulation of the argument hem_id leads to cross site scripting. The attack can be… | |
| Modificada | Media (4.3) | 0.53% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | |
| Modificada | Media (6.5) | 0.73% | — | Cisco Packaged Contact Center EnterpriseCisco Unified Contact Center EnterpriseCisco Unified Contact Center ExpressCisco Unified Intelligence Center | 3/3/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities. | |
| Modificada | Media (6.1) | 0.56% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 2/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Health Center Patient Record Management System 1.0. This vulnerability affects unknown code of the file admin/fecalysis_form.php. The manipulation of the argument itr_no leads to cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Media (5.5) | 0.20% | — | HP Oneview FOR Vmware Vcenter | 1/3/2023 | 17/6/2026 | HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password. | |
| Modificada | Alta (8.1) | 0.28% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center Analyzer | 28/2/2023 | 17/6/2026 | Improper Certificate Validation vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component) allows Man in the Middle Attack.This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00;… | |
| Modificada | Alta (7.1) | 0.15% | — | Hitachi OPS Center Analyzer | 28/2/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local users to read and write specific files.This issue affects Hitachi Ops Center Analyzer: from 10.9.0-00 before 10.9.0-01. | |
| Modificada | Alta (7.1) | 0.15% | — | Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+1 | 28/2/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,… | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Kardex Control Center | 15/2/2023 | 17/6/2026 | Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of including local files, as well as remote… | |
| Modificada | Alta (7.5) | 0.60% | — | Mitel Micontact Center Business | 13/2/2023 | 17/6/2026 | El componente ccmweb del servidor Mitel MiContact Center Business 9.2.2.0 a 9.4.1.0 podría permitir a un atacante no autenticado descargar archivos arbitrarios, debido a una restricción insuficiente de los parámetros de URL. Un exploit exitoso podría permitir el acceso a información confidencial. | |
| Modificada | Baja (3.3) | 0.17% | — | Dell Command | Integration Suite FOR System Center | 13/2/2023 | 17/6/2026 | Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Alienware Command Center | 10/2/2023 | 17/6/2026 | Dell Alienware Command Center en su versión 5.5.37.0 y anteriores contienen una vulnerabilidad de validación de entrada incorrecta. Un usuario malintencionado autenticado local podría potencialmente enviar entradas maliciosas a una canalización con nombre para elevar los privilegios en el sistema. | |
| Modificada | Alta (7.5) | 1.8% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check… | |
| Modificada | Alta (7.4) | 60% | — | OpensslStormshield Management CenterStormshield Network Security | 8/2/2023 | 17/6/2026 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by… | |
| Modificada | Alta (7.5) | 1.8% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does… | |
| Modificada | Alta (7.5) | 4.5% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new… | |
| Modificada | Crítica (9.8) | 74% | — | Zohocorp Manageengine Supportcenter Plus | 1/2/2023 | 17/6/2026 | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Rugged Control Center | 1/2/2023 | 17/6/2026 | Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attacker could potentially exploit this vulnerability, leading to an Escalation of privileges. | |
| Modificada | Alta (8.8) | 0.54% | — | Schneider-electric Data Center Expert | 30/1/2023 | 17/6/2026 | Existe una vulnerabilidad CWE 502: deserialización de datos no confiables que podría permitir que el código se ejecute de forma remota en el servidor cuando se publican datos deserializados de manera insegura en el servidor web. Productos afectados: Data Center Expert (versiones anteriores a V7.9.0) | |
| Modificada | Crítica (9.8) | 0.54% | — | Schneider-electric Data Center Expert | 30/1/2023 | 17/6/2026 | Existe una vulnerabilidad CWE-522: Credenciales insuficientemente protegidas que podría provocar un acceso no deseado a una instancia de DCE cuando un tercero malintencionado lo realiza a través de una red. Este CVE es único de CVE-2022-32518. Productos afectados: Data Center Expert (versiones anteriores a V7.9.0) | |
| Modificada | Crítica (9.8) | 0.48% | — | Schneider-electric Data Center Expert | 30/1/2023 | 17/6/2026 | Existe una vulnerabilidad CWE-257: almacenamiento de contraseñas en un formato recuperable que podría provocar un acceso no deseado a una instancia de DCE cuando un tercero malintencionado lo realiza a través de una red. Productos afectados: Data Center Expert (versiones anteriores a V7.9.0) | |
| Modificada | Crítica (9.8) | 0.54% | — | Schneider-electric Data Center Expert | 30/1/2023 | 17/6/2026 | Existe una vulnerabilidad CWE-522: Credenciales insuficientemente protegidas que podría provocar un acceso no deseado a una instancia de DCE cuando un tercero malintencionado lo realiza a través de una red. Este CVE es único de CVE-2022-32520. Productos afectados: Data Center Expert (versiones anteriores a V7.9.0) |