Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
2678 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 14/6/2023 | 17/6/2026 | A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. | |
| Modificada | Media (5.3) | 0.62% | — | Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie FirmwarePhoenixcontact FL Mguard 4302 Firmware+22 | 13/6/2023 | 17/6/2026 | Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks. | |
| Modificada | Alta (7.8) | 0.20% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (8.8) | 2.1% | — | Sitecore Experience Platform | 6/6/2023 | 17/6/2026 | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML. | |
| Modificada | Alta (8.8) | 2.5% | — | Sitecore Experience Platform | 6/6/2023 | 17/6/2026 | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /sitecore/shell/Invoke.aspx. | |
| Modificada | Alta (7.5) | 1.4% | — | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 6/6/2023 | 17/6/2026 | An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules. | |
| Modificada | Media (5.4) | 0.47% | — | Corebos | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc. | |
| Modificada | Media (6.5) | 0.32% | — | Corebos | 2/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Media (5.4) | 0.51% | — | Corebos | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Media (5.4) | 0.52% | — | Tsolucio Corebos | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Media (5.4) | 0.57% | — | Corebos | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Crítica (9.8) | 0.60% | — | Corebos | 2/6/2023 | 17/6/2026 | Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. | |
| Modificada | Media (4.3) | 0.41% | — | Bluetooth Core Specification | 2/6/2023 | 17/6/2026 | Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully extract the permanent, unique Bluetooth MAC identifier, along with device capabilities… | |
| Modificada | Alta (8.8) | 0.85% | — | Pimcore | 30/5/2023 | 17/6/2026 | Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | |
| Modificada | Alta (8.8) | 0.92% | — | Pimcore | 30/5/2023 | 17/6/2026 | Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23. | |
| Modificada | Crítica (9.8) | 0.77% | — | Cbot CoreCbot Panel | 25/5/2023 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. | |
| Modificada | Media (4.3) | 0.21% | — | Cbot CoreCbot Panel | 25/5/2023 | 17/6/2026 | Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. |