Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
2678 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.30% | — | Cbot CoreCbot Panel | 25/5/2023 | 17/6/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in CBOT Chatbot allows Adversary in the Middle (AiTM). This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. | |
| Modificada | Crítica (9.8) | 0.69% | — | Cbot CoreCbot Panel | 25/5/2023 | 17/6/2026 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. | |
| Modificada | Alta (8.8) | 0.68% | — | Cbot CoreCbot Panel | 25/5/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. | |
| Modificada | Crítica (9.8) | 0.64% | — | Cbot CoreCbot Panel | 25/5/2023 | 17/6/2026 | Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. | |
| Analizada | Media (4.9) | 0.55% | — | Pimcore Customer Management Framework | 25/5/2023 | 17/6/2026 | Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10. | |
| Modificada | Crítica (9.8) | 1.7% | — | Sitecore Experience Platform | 23/5/2023 | 17/6/2026 | Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx. | |
| Modificada | Alta (7.5) | 1.6% | — | Sitecore Experience Platform | 22/5/2023 | 17/6/2026 | Directory Traversal vulnerability in Sitecore Experience Platform through 10.2 allows remote attackers to download arbitrary files via crafted command to download.aspx | |
| Modificada | Media (6.5) | 1.5% | — | Sitecore Experience Platform | 22/5/2023 | 17/6/2026 | Directory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrary files via Urlhandle. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Poweredge R740 FirmwareDell Poweredge R740xd FirmwareDell Poweredge R640 FirmwareDell Poweredge R940 Firmware+26 | 22/5/2023 | 17/6/2026 | Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading… | |
| Modificada | Alta (7.5) | 1.4% | — | Bitcoin Core | 22/5/2023 | 17/6/2026 | Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023. | |
| Modificada | Alta (7.2) | 0.94% | — | Pimcore Customer Management Framework | 17/5/2023 | 17/6/2026 | SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10. | |
| Modificada | Media (5.4) | 0.48% | — | Pimcore | 16/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. | |
| Modificada | Media (6.1) | 0.61% | — | Vinteo Video Core | 12/5/2023 | 17/6/2026 | Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser. | |
| Modificada | Media (4.3) | 0.76% | — | Pimcore Customer Management Framework | 11/5/2023 | 17/6/2026 | The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management. In `pimcore/customer-management-framework-bundle` prior to version 3.3.9, business logic errors are possible in the `Conditions` tab since the counter can be a negative number. This vulnerability is capable of the… | |
| Modificada | Media (4.8) | 0.58% | — | Pimcore | 10/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Alta (7.8) | 0.41% | — | Pimcore Customer Management Framework | 10/5/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+463 | 10/5/2023 | 17/6/2026 | Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Xeon E-2314 FirmwareIntel Xeon E-2324g FirmwareIntel Xeon E-2334 FirmwareIntel Xeon E-2336 Firmware+269 | 10/5/2023 | 17/6/2026 | Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.4) | 0.50% | — | Pimcore | 10/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.50% | — | Pimcore | 10/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.50% | — | Pimcore | 10/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.5) | 0.15% | — | SAP S4coreSAP Vendor Master Hierarchy | 9/5/2023 | 17/6/2026 | Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to… | |
| Modificada | Media (5.4) | 0.37% | — | SAP Customer Relationship Management Webclient UISAP S4fndSapscore | 9/5/2023 | 17/6/2026 | SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After… | |
| Modificada | Alta (7.5) | 0.80% | — | Pimcore | 8/5/2023 | 17/6/2026 | Pimcore is an open source data and experience management platform. Versions of Pimcore prior to 10.5.18 are vulnerable to path traversal. The impact of this path traversal and arbitrary extension is limited to creation of arbitrary files and appending data to existing files. When combined with the SQL Injection, the… | |
| Modificada | Alta (8.6) | 0.30% | — | Samsung Core Services | 4/5/2023 | 17/6/2026 | Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox. |