Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
2384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.8% | — | Cyberpower Powerpanel Server | 14/8/2023 | 17/6/2026 | When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the… | |
| Modificada | Crítica (9.8) | 0.88% | — | Cyberpower Powerpanel Server | 14/8/2023 | 17/6/2026 | A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator by… | |
| Modificada | Crítica (9.8) | 1.6% | — | Cyberpower Powerpanel Server | 14/8/2023 | 17/6/2026 | An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log… | |
| Modificada | Crítica (9.8) | 0.47% | — | Cyberpower Powerpanel ServerDataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 Firmware+19 | 14/8/2023 | 17/6/2026 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary… | |
| Modificada | Alta (7.2) | 0.78% | — | Cyberpower Powerpanel ServerDataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 Firmware+19 | 14/8/2023 | 17/6/2026 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the… | |
| Modificada | Alta (8.8) | 1.3% | — | Cyberpower Powerpanel ServerDataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 Firmware+19 | 14/8/2023 | 17/6/2026 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system. | |
| Modificada | Crítica (9.1) | 0.63% | — | Empowerid | 11/8/2023 | 17/6/2026 | EmpowerID antes de 7.205.0.1 permite a un atacante saltarse un requisito MFA (autenticación multifactor) si se conoce el primer factor (nombre de usuario y contraseña), porque el primer factor es suficiente para cambiar la dirección de correo electrónico de una cuenta, y el producto enviaría entonces códigos MFA a la… | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Armor Powerflex Firmware | 8/8/2023 | 17/6/2026 | A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log. Threat actors could exploit this vulnerability by sending an influx of network commands, causing the product to generate an influx of event log traffic at a high rate. If… | |
| Modificada | Media (5.3) | 2.0% | — | SAP Powerdesigner | 8/8/2023 | 17/6/2026 | SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory. | |
| Modificada | Crítica (9.8) | 4.8% | — | SAP Powerdesigner | 8/8/2023 | 17/6/2026 | SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy. | |
| Modificada | Alta (7.8) | 0.22% | — | SAP Powerdesigner | 8/8/2023 | 17/6/2026 | SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the behavior of the application. | |
| Modificada | Media (5.7) | 0.21% | — | Empowerid | 6/8/2023 | 17/6/2026 | A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknown processing of the component Multi-Factor Authentication Code Handler. The manipulation leads to information disclosure. The complexity of an attack is rather high. The exploitation is known to be… | |
| Modificada | Alta (7.8) | 0.26% | — | Psappdeploytoolkit Powershell APP Deployment Toolkit | 1/8/2023 | 17/6/2026 | In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability in the default configuration may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 30% | — | Powerjob | 28/7/2023 | 17/6/2026 | PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail. | |
| Modificada | Alta (7.8) | 0.20% | — | Dell Power Manager | 27/7/2023 | 17/6/2026 | Dell Power Manager en versiones de la 3.3 hasta la 3.14 contiene una vulnerabilidad de control de acceso inadecuado. Un usuario malintencionado con pocos privilegios podría aprovechar esta vulnerabilidad para ejecutar código arbitrario con acceso limitado. | |
| Modificada | Alta (7.5) | 1.4% | — | KeylimeRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+5 | 24/7/2023 | 17/6/2026 | Se encontró una falla en Keylime. Debido a su naturaleza de bloqueo, el registrador de Keylime está sujeto a una denegación de servicio remota contra sus conexiones SSL. Esta falla permite a un atacante agotar todas las conexiones disponibles. | |
| Modificada | Media (4.9) | 0.54% | — | Dell Powerstoreos | 21/7/2023 | 17/6/2026 | Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure. | |
| Modificada | Crítica (9.8) | 1.1% | — | Voltronicpower Snmp WEB PRO | 12/7/2023 | 17/6/2026 | The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances… | |
| Modificada | Media (5.4) | 0.55% | — | Microsoft Power Apps | 11/7/2023 | 17/6/2026 | Microsoft Power Apps (online) Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 0.93% | — | Rockwellautomation Powermonitor 1000 Firmware | 11/7/2023 | 17/6/2026 | The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote… | |
| Modificada | Media (6.1) | 0.63% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Linuxone+1 | 7/7/2023 | 17/6/2026 | Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri. | |
| Modificada | Alta (7.5) | 0.52% | — | Redhat Openshift Container PlatformRedhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR PowerRedhat Openshift Container Platform IBM Z Systems+1 | 5/7/2023 | 17/6/2026 | A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated. | |
| Modificada | Media (6.5) | 0.64% | — | Rapidload Power-up FOR Autoptimize | 22/6/2023 | 17/6/2026 | Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 versions. | |
| Modificada | Alta (7.8) | 0.12% | — | Dell Powerstoret OS | 22/6/2023 | 17/6/2026 | Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privileged user to install a malicious binary by bypassing the existing cryptographic signature checks | |
| Modificada | Media (6.1) | 0.39% | — | Subnet Powersystem Center | 19/6/2023 | 17/6/2026 | SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications. |