Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2771▲ 6 respecto a la semana anterior
Críticas / altas1285▼ 246 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
5320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.46% | — | Paloaltonetworks Pan-os | 12/7/2023 | 17/6/2026 | A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated administrator with the privilege to commit a specifically created configuration to read local files and resources from the system. | |
| Modificada | Media (6.5) | 1.2% | — | Jenkins Mathworks Polyspace | 12/7/2023 | 17/6/2026 | Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jenkins controller file systems. | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Alta (7.8) | 0.35% | — | 3DS 3dexperience Solidworks | 12/7/2023 | 17/6/2026 | Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially… | |
| Modificada | Alta (7.8) | 0.36% | — | 3DS 3dexperience Solidworks | 12/7/2023 | 17/6/2026 | A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file. | |
| Modificada | Alta (8.8) | 12% | — | Ruijienetworks Bcr810w Firmware | 10/7/2023 | 17/6/2026 | A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Media (5.5) | 0.18% | — | Citrix Workspace | 10/7/2023 | 17/6/2026 | A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. | |
| Modificada | Alta (7.5) | 0.64% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | There is an unauthenticated buffer overflow vulnerability in the process controlling the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in a Denial-of-Service (DoS) condition affecting the web-based management interface of the controller. | |
| Modificada | Media (6.1) | 0.46% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected… | |
| Modificada | Media (6.5) | 0.55% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level. | |
| Modificada | Media (6.5) | 0.55% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level. | |
| Modificada | Alta (8.1) | 0.72% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system. | |
| Modificada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 1.4% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Modificada | Alta (7.2) | 1.6% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the… | |
| Modificada | Media (6.1) | 0.62% | — | Arubanetworks Arubaos | 5/7/2023 | 17/6/2026 | A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the… | |
| Modificada | Alta (7) | 0.13% | — | HP 260 G4 Desktop Mini FirmwareHP T430 FirmwareHP T628 FirmwareHP 240 G10 Firmware+55 | 30/6/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability. | |
| Modificada | Media (5.4) | 0.37% | — | Palantir Foundry Workspace-server | 29/6/2023 | 17/6/2026 | A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with… | |
| Modificada | Alta (7.8) | 0.30% | — | ARM NN Android Neural Networks Driver | 29/6/2023 | 17/6/2026 | A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Android-NN-Driver before 23.02. | |
| Modificada | Alta (7.8) | 0.35% | — | Autodesk 3DS MAXAutodesk NavisworksAutodesk RevitAutodesk Vred | 27/6/2023 | 17/6/2026 | A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Alta (7.8) | 0.26% | — | Autodesk Navisworks | 27/6/2023 | 17/6/2026 | A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. | |
| Modificada | Alta (7.8) | 0.25% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 23/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Crítica (9.8) | 0.94% | — | L7-networks InstantqosL7-networks Instantscan | 16/6/2023 | 17/6/2026 | La función de carga de archivos de L7 Networks InstantScan IS-8000 e InstantQoS IQ-8000 no restringen la carga de archivos de tipo peligroso. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para cargar y ejecutar archivos ejecutables arbitrarios para realizar comandos arbitrarios del sistema o… |