Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▲ 5 respecto a la semana anterior
Críticas / altas1275▼ 253 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
2680 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment feature of Goobi viewer core prior to version 23.03. An attacker could create a specially crafted comment, resulting in the execution of… | |
| Modificada | Media (6.1) | 0.44% | — | Intranda Goobi Viewer Core | 6/4/2023 | 17/6/2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi viewer core prior to version 23.03 when evaluating the LOGID parameter. An attacker could trick a user into following a specially crafted… | |
| Modificada | Alta (8.8) | 2.1% | — | Coredial Sipxcom | 4/4/2023 | 17/6/2026 | CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This can also be leveraged to gain remote… | |
| Modificada | Alta (8.8) | 2.5% | 💥 PoC | Coredial Sipxcom | 4/4/2023 | 17/6/2026 | CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the `daemon` user on a sipXcom server can overwrite a service file, and escalate their privileges to `root`. | |
| Modificada | Media (5.4) | 0.57% | — | Pimcore Perspective Editor | 3/4/2023 | 17/6/2026 | Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Version… | |
| Modificada | Alta (7.8) | 0.87% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.87% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.87% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Media (5.5) | 0.83% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 0.87% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Alta (7.8) | 0.93% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of… | |
| Modificada | Media (5.5) | 0.83% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Media (5.5) | 0.83% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Media (5.5) | 0.81% | — | Coreldraw | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.5.0.506. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Crítica (9.8) | 0.98% | — | Atrocore | 29/3/2023 | 17/6/2026 | In Atrocore 1.5.25, the Create Import Feed option with glyphicon-glyphicon-paperclip function is vulnerable to Unauthenticated File upload. | |
| Modificada | Media (5.4) | 0.42% | — | Pimcore | 29/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20. | |
| Modificada | Media (5.4) | 0.46% | — | Pimcore | 29/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20. | |
| Modificada | Media (5.4) | 0.44% | — | Pimcore | 29/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20. | |
| Modificada | Media (5.4) | 0.44% | — | Pimcore | 29/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20. | |
| Modificada | Alta (7) | 0.36% | — | Musescore | 28/3/2023 | 17/6/2026 | Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code. | |
| Modificada | Alta (8) | 0.86% | — | Pimcore | 22/3/2023 | 17/6/2026 | Pimcore is an open source data and experience management platform. Prior to version 10.5.19, since a user with 'report' permission can already write arbitrary SQL queries and given the fact that this endpoint is using the GET method (no CSRF protection), an attacker can inject an arbitrary query by manipulating a user… | |
| Modificada | Alta (8.8) | 63% | — | Pimcore | 22/3/2023 | 17/6/2026 | SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19. | |
| Modificada | Media (5.4) | 0.54% | — | Corebos | 21/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0. | |
| Modificada | Media (4.8) | 0.40% | — | Pimcore | 20/3/2023 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19. | |
| Modificada | Media (6.1) | 0.54% | — | Pimcore | 20/3/2023 | 17/6/2026 | Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to… |