Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
2678 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.48% | — | Pimcore | 28/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (4.9) | 1.0% | — | Pimcore | 27/4/2023 | 17/6/2026 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the `/admin/misc/script-proxy` API endpoint that is accessible by an authenticated administrator user is vulnerable to arbitrary JavaScript and CSS file read via the `scriptPath` and `scripts` parameters. The `scriptPath`… | |
| Modificada | Alta (8.8) | 0.79% | — | Pimcore | 27/4/2023 | 17/6/2026 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, a SQL Injection vulnerability exists in the admin translations API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually. | |
| Modificada | Alta (8.8) | 0.79% | — | Pimcore | 27/4/2023 | 17/6/2026 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, A SQL injection vulnerability exists in the translation export API. Users should update to version 10.5.21 to receive a patch or, as a workaround, or apply the patch manually. | |
| Modificada | Alta (8.8) | 0.72% | — | Pimcore | 27/4/2023 | 17/6/2026 | Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the admin search find API has a SQL injection vulnerability. Users should upgrade to version 10.5.21 to receive a patch or, as a workaround, apply the patch manually. | |
| Modificada | Media (5.4) | 0.38% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.42% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (6.1) | 1.1% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.48% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.52% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Alta (8.8) | 0.91% | — | Pimcore | 27/4/2023 | 17/6/2026 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (6.5) | 0.67% | — | Pimcore | 27/4/2023 | 17/6/2026 | Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.40% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.40% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.51% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.4) | 0.56% | — | Pimcore | 27/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21. | |
| Modificada | Media (5.9) | 1.0% | 💥 PoC | Trustwallet Trust Wallet Browser ExtensionTrustwallet Trust Wallet Core | 27/4/2023 | 17/6/2026 | Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in December 2022 and March 2023. This occurs because the mt19937 Mersenne Twister takes a single 32-bit value as an input seed, resulting in only… | |
| Modificada | Media (5.3) | 1.3% | 💥 PoC | Oracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core PolicyOracle Mysql ConnectorsNetapp Active IQ Unified Manager+2 | 18/4/2023 | 17/6/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require… | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Mediawiki Score | 15/4/2023 | 17/6/2026 | The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted… | |
| Modificada | Alta (7.5) | 1.1% | — | Atrocore Atropim | 14/4/2023 | 17/6/2026 | Atropim 1.5.26 is vulnerable to Directory Traversal. | |
| Modificada | Media (5.4) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images… | |
| Modificada | Media (4.6) | 0.32% | — | SAP Abap PlatformSAP Application Interface FrameworkSAP BasisSAP S4core | 11/4/2023 | 17/6/2026 | The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when using nicknames. An attacker could create a user account and enter malicious scripts into their profile's… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted… |