Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
3429 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.50% | — | Geminilabs Site Reviews | 2/5/2023 | 17/6/2026 | The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.5) | 0.19% | — | HP OneviewHPE Oneview Global Dashboard | 25/4/2023 | 17/6/2026 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | |
| Modificada | Media (5.5) | 0.17% | — | HP Oneview | 25/4/2023 | 17/6/2026 | An HPE OneView appliance dump may expose SNMPv3 read credentials | |
| Modificada | Alta (7.1) | 0.17% | — | HP Oneview | 25/4/2023 | 17/6/2026 | An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules | |
| Modificada | Alta (7.8) | 0.17% | — | HP Oneview | 25/4/2023 | 17/6/2026 | An HPE OneView appliance dump may expose SAN switch administrative credentials | |
| Modificada | Media (5.5) | 0.17% | — | HP Oneview | 25/4/2023 | 17/6/2026 | An HPE OneView appliance dump may expose OneView user accounts | |
| Modificada | Media (5.5) | 0.17% | — | HP Oneview | 25/4/2023 | 17/6/2026 | An HPE OneView appliance dump may expose proxy credential settings | |
| Modificada | Media (5.4) | 0.44% | — | Ms-reviews Project Ms-reviews | 24/4/2023 | 17/6/2026 | The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.36% | — | Simple PDF Viewer Project Simple PDF Viewer | 23/4/2023 | 17/6/2026 | Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions. | |
| Modificada | Media (5.5) | 0.19% | — | HP Oneview | 14/4/2023 | 17/6/2026 | La opción "Migrate server hardware" de los appliance virtuales HPE OneView puede exponer información sensible en un HPE volcado de soporte de OneView. | |
| Modificada | Media (5.5) | 0.18% | — | HPE Oneview Global Dashboard | 14/4/2023 | 17/6/2026 | An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials | |
| Modificada | Media (6.3) | 0.09% | — | Siemens Simatic Ipc647d FirmwareSiemens Simatic Ipc847d FirmwareSiemens Simatic Ipc1047 FirmwareMicrochip Maxview Storage Manager | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when using nicknames. An attacker could create a user account and enter malicious scripts into their profile's… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted… | |
| Modificada | Media (5.5) | 0.55% | — | Irfanview | 4/4/2023 | 17/6/2026 | Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0. | |
| Modificada | Media (6.5) | 0.71% | — | Jenkins Remote-jobs-view | 2/4/2023 | 17/6/2026 | Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (5.4) | 0.46% | — | Jenkins Pipeline Aggregator View | 2/4/2023 | 17/6/2026 | Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission. | |
| Modificada | Alta (7.8) | 0.94% | — | Bentley MicrostationBentley View | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.94% | — | Bentley MicrostationBentley View | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Media (5.5) | 0.61% | — | Bentley MicrostationBentley View | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 0.94% | — | Bentley MicrostationBentley View | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.94% | — | Bentley MicrostationBentley View | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.94% | — | Bentley MicrostationBentley View | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.95% | — | Bentley MicrostationBentley View | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… |