Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

3429 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.50%—Geminilabs Site Reviews2/5/202317/6/2026
The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (5.5)0.19%—HP OneviewHPE Oneview Global Dashboard25/4/202317/6/2026
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
ModificadaMedia (5.5)0.17%—HP Oneview25/4/202317/6/2026
An HPE OneView appliance dump may expose SNMPv3 read credentials
ModificadaAlta (7.1)0.17%—HP Oneview25/4/202317/6/2026
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
ModificadaAlta (7.8)0.17%—HP Oneview25/4/202317/6/2026
An HPE OneView appliance dump may expose SAN switch administrative credentials
ModificadaMedia (5.5)0.17%—HP Oneview25/4/202317/6/2026
An HPE OneView appliance dump may expose OneView user accounts
ModificadaMedia (5.5)0.17%—HP Oneview25/4/202317/6/2026
An HPE OneView appliance dump may expose proxy credential settings
ModificadaMedia (5.4)0.44%—Ms-reviews Project Ms-reviews24/4/202317/6/2026
The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.36%—Simple PDF Viewer Project Simple PDF Viewer23/4/202317/6/2026
Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions.
ModificadaMedia (5.5)0.19%—HP Oneview14/4/202317/6/2026
La opción "Migrate server hardware" de los appliance virtuales HPE OneView puede exponer información sensible en un HPE volcado de soporte de OneView.
ModificadaMedia (5.5)0.18%—HPE Oneview Global Dashboard14/4/202317/6/2026
An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials
ModificadaMedia (6.3)0.09%—Siemens Simatic Ipc647d FirmwareSiemens Simatic Ipc847d FirmwareSiemens Simatic Ipc1047 FirmwareMicrochip Maxview Storage Manager11/4/202317/6/2026
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when using nicknames. An attacker could create a user account and enter malicious scripts into their profile's…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of…
ModificadaMedia (6.1)0.44%—Intranda Goobi Viewer Core6/4/202317/6/2026
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted…
ModificadaMedia (5.5)0.55%—Irfanview4/4/202317/6/2026
Irfanview v4.62 allows a user-mode write access violation via a crafted JPEG 2000 file starting at JPEG2000+0x0000000000001bf0.
ModificadaMedia (6.5)0.71%—Jenkins Remote-jobs-view2/4/202317/6/2026
Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (5.4)0.46%—Jenkins Pipeline Aggregator View2/4/202317/6/2026
Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission.
ModificadaAlta (7.8)0.94%—Bentley MicrostationBentley View29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.94%—Bentley MicrostationBentley View29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaMedia (5.5)0.61%—Bentley MicrostationBentley View29/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaAlta (7.8)0.94%—Bentley MicrostationBentley View29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.94%—Bentley MicrostationBentley View29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.94%—Bentley MicrostationBentley View29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (7.8)0.95%—Bentley MicrostationBentley View29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…