Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
2384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.55% | — | Rapidload Power-up FOR Autoptimize | 10/3/2023 | 17/6/2026 | The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete the plugin's cache. | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa | WebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+19 | 6/3/2023 | 8/10/2026 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. | |
| Modificada | Media (6.7) | 0.11% | — | Dell Powerscale Onefs | 2/3/2023 | 17/6/2026 | Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerability in certificate management, leading to a potential system takeover. | |
| Modificada | Alta (7.1) | 0.15% | — | Dell EMC Powerscale Onefs | 28/2/2023 | 17/6/2026 | Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability to overwrite arbitrary files causing denial of service. | |
| Modificada | Alta (7.8) | 0.57% | — | Techpowerup Dram Calculator FOR Ryzen | 26/2/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in TechPowerUp Ryzen DRAM Calculator 1.2.0.5. This issue affects some unknown processing in the library WinRing0x64.sys. The manipulation leads to improper initialization. Local access is required to approach this attack. The exploit has been disclosed… | |
| Modificada | Alta (7.8) | 0.40% | — | Techpowerup Realtemp | 26/2/2023 | 17/6/2026 | A vulnerability classified as critical was found in TechPowerUp RealTemp 3.7.0.0. This vulnerability affects unknown code in the library WinRing0x64.sys. The manipulation leads to improper initialization. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. VDB-221806… | |
| Modificada | Alta (8.8) | 0.21% | — | ABB Infinity DC Power PlantABB Ne843 S | 24/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+8 | 23/2/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands… | |
| Modificada | Media (5.4) | 0.40% | — | Tibco EBXProduct AND Service Catalog Powered BY Tibco EBX | 22/2/2023 | 17/6/2026 | The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s… | |
| Modificada | Alta (8.2) | 0.78% | — | Microsoft Power BI Report Server | 14/2/2023 | 19/8/2026 | Power BI Report Server Spoofing Vulnerability | |
| Modificada | Media (4.3) | 0.51% | — | Gptaipower GPT AI Power | 13/2/2023 | 17/6/2026 | El complemento GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training de WordPress anterior a 1.4.38 no realiza ningún tipo de verificación de privilegios o nonce antes de permitir que los usuarios que han iniciado sesión modifiquen publicaciones arbitrarias. | |
| Modificada | Media (6.8) | 0.23% | — | Deyeinverter Inverter FirmwareRevolt-power Inverter FirmwareBosswerk Inverter Firmware | 13/2/2023 | 17/6/2026 | A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation with the input 12345678 leads to use of hard-coded password. It is possible to… | |
| Modificada | Media (5.7) | 0.23% | — | Dell Evasa Provider Virtual ApplianceDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance | 13/2/2023 | 17/6/2026 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an authorization bypass vulnerability, allowing users to perform actions in which they are not authorized. | |
| Modificada | Crítica (9.8) | 0.66% | — | Gruparge Smartpower | 12/2/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01. | |
| Modificada | Media (5.4) | 0.36% | — | Gruparge Smartpower WEB | 12/2/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS). This issue affects Smartpower Web: before 23.01.01. | |
| Modificada | Alta (8.8) | 0.65% | — | Gruparge Smartpower WEB | 12/2/2023 | 17/6/2026 | Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01. | |
| Modificada | Alta (8.8) | 0.65% | — | Gruparge Smartpower WEB | 12/2/2023 | 17/6/2026 | Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01. | |
| Modificada | Crítica (9.8) | 0.72% | — | Gruparge Smartpower WEB | 12/2/2023 | 17/6/2026 | Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion. This issue affects Smartpower Web: before 23.01.01. | |
| Modificada | Media (6.1) | 0.38% | — | Gruparge Smartpower WEB | 12/2/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS). This issue affects Smartpower Web: before 23.01.01. | |
| Modificada | Media (5.4) | 0.36% | — | Gruparge Smartpower WEB | 12/2/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows Cross-Site Scripting (XSS). This issue affects Smartpower Web: before 23.01.01. | |
| Modificada | Media (6.5) | 0.56% | — | Gruparge Smartpower WEB | 12/2/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Group Arge Energy and Control Systems Smartpower Web allows : Server Side Request Forgery. This issue affects Smartpower Web: before 23.01.01. | |
| Modificada | Alta (8.8) | 1.4% | — | Dell Evasa Provider Virtual ApplianceDell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance | 11/2/2023 | 17/6/2026 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying system. | |
| Modificada | Media (4.8) | 0.34% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Stored Cross-site Scripting Vulnerability. An authenticated admin user could potentially exploit this vulnerability, to hijack user sessions or trick a victim application user into unknowingly send arbitrary requests to the server. | |
| Modificada | Media (6.7) | 0.42% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with version 3.3 contains Privilege Escalation vulnerability. An authenticated admin user could potentially exploit this issue and gain unrestricted control/code execution on the system as root. | |
| Modificada | Media (6) | 0.18% | — | Dell Powerpath Management Appliance | 11/2/2023 | 17/6/2026 | PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit the issue that leads to view and modifying sensitive information stored in the application. |