Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
2110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.91% | — | Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System | 11/7/2023 | 17/6/2026 | A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Duty/AjaxHandle/UploadHandler.ashx of the component Duty Module. The manipulation of the… | |
| Modificada | Media (6.1) | 0.60% | — | Phpgurukul Online Security Guards Hiring System | 10/7/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box. | |
| Modificada | Media (6.1) | 0.63% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 10/7/2023 | 17/6/2026 | Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?page=categories" Category item. | |
| Modificada | Alta (7.2) | 0.90% | — | Food Ordering System Project Food Ordering System | 6/7/2023 | 17/6/2026 | A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter. | |
| Modificada | Media (5.7) | 0.29% | — | SAP Digital ManufacturingSAP Plant Connectivity | 13/6/2023 | 17/6/2026 | SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the internal network could send service requests… | |
| Modificada | Crítica (9.8) | 1.3% | — | Percona Monitoring AND Management | 6/6/2023 | 17/6/2026 | In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made against unauthenticated API routes, to… | |
| Modificada | Crítica (9.8) | 0.80% | — | Erikogluteknoloji Energy Monitoring | 2/6/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypass. This issue affects ErMon: before 230602. | |
| Modificada | Alta (7.5) | 0.91% | — | Vmware Spring Boot | 26/5/2023 | 17/6/2026 | In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache. | |
| Modificada | Media (5.5) | 0.23% | — | ABB Platform Engineering ToolsABB QCS 800xa FirmwareABB QCS Ac450 Firmware | 22/5/2023 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to… | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Oneapi AI Analytics ToolkitIntel Oneapi Base ToolkitIntel Oneapi DL Framework Developer ToolkitIntel Oneapi HPC Toolkit+2 | 12/5/2023 | 17/6/2026 | Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 0.75% | — | Spring-boot-actuator-logview Project Spring-boot-actuator-logview | 11/5/2023 | 17/6/2026 | spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view. | |
| Modificada | Media (6.1) | 0.65% | 💥 PoC | Xwiki RenderingXwiki | 10/5/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known… | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Oretnom23 Food Ordering Management System | 9/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the component Registration. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this… | |
| Modificada | Crítica (9.8) | 0.98% | 💥 PoC | Online Pizza Ordering System Project Online Pizza Ordering System | 8/5/2023 | 17/6/2026 | SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter. | |
| Modificada | Crítica (9.8) | 0.98% | — | Oretnom23 Online Food Ordering System | 5/5/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Alta (7.1) | 0.17% | — | F5 Nginx API Connectivity ManagerF5 Nginx Instance ManagerF5 Nginx Security Monitoring | 3/5/2023 | 17/6/2026 | NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.1) | 0.53% | — | Netapp Cloud BackupNetapp Ontap Select DeployF5 Nginx API Connectivity ManagerF5 Nginx Instance Manager+1 | 3/5/2023 | 17/6/2026 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Crítica (9.8) | 3.6% | 💥 Exploit | Online Pizza Ordering System Project Online Pizza Ordering System | 23/4/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/ajax.php?action=save_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.1% | — | Vmware Spring Boot | 20/4/2023 | 17/6/2026 | In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to… | |
| Modificada | Media (6.3) | 0.65% | — | Vmware Spring SecurityNetapp Active IQ Unified Manager | 19/4/2023 | 17/6/2026 | In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the… | |
| Modificada | Alta (7.5) | 0.71% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 18/4/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service. | |
| Modificada | Crítica (9.8) | 1.2% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 18/4/2023 | 17/6/2026 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface. | |
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 18/4/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface. | |
| Modificada | Alta (8.8) | 0.32% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 18/4/2023 | 17/6/2026 | A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account. |