Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
6918 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.49% | — | Intuitive Custom Post Order Project Intuitive Custom Post Order | 21/2/2023 | 17/6/2026 | The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order | |
| Modificada | Media (6.1) | 0.49% | — | Cention-chatserver Project Cention-chatserver | 21/2/2023 | 17/6/2026 | A vulnerability was found in cention-chatserver 3.8.0-rc1. It has been declared as problematic. Affected by this vulnerability is the function _formatBody of the file lib/InternalChatProtocol.fe. The manipulation of the argument body leads to cross site scripting. The attack can be launched remotely. Upgrading to… | |
| Modificada | Media (6.1) | 0.68% | — | Mind-elixir Project Mind-elixir | 20/2/2023 | 17/6/2026 | Mind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting when handling untrusted menus. This issue is patched in version 0.18.1 | |
| Modificada | Alta (7.5) | 0.44% | — | Notaryproject Notation-go | 20/2/2023 | 17/6/2026 | notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation-go users will find their application using excessive memory when verifying signatures. The application will be killed, and thus availability is impacted. The problem has… | |
| Modificada | Alta (7.5) | 1.2% | — | Gnome EpiphanyFedoraproject Fedora | 20/2/2023 | 17/6/2026 | In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts. | |
| Modificada | Crítica (9.8) | 1.2% | — | Java-xmlbuilder Project Java-xmlbuilder | 19/2/2023 | 17/6/2026 | A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. Upgrading to version 1.2 is able to address this issue. The name of the patch is… | |
| Modificada | Crítica (9.8) | 0.82% | — | Hotels Server Project Hotels Server | 17/2/2023 | 17/6/2026 | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter. | |
| Modificada | Alta (7.5) | 20% | 💥 PoC | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+2 | 17/2/2023 | 17/6/2026 | Un problema en el componente urllib.parse de Python anterior a 3.11.4 permite a los atacantes eludir los métodos de listas de bloqueo proporcionando una URL que comienza con caracteres en blanco. | |
| Modificada | Alta (7.5) | 0.78% | — | Media-server Project Media-server | 15/2/2023 | 17/6/2026 | Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows attackers to cause a denial of service. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Crítica (9.8) | 0.63% | — | Shaarlier Project Shaarlier | 9/2/2023 | 17/6/2026 | Se encontró una vulnerabilidad en Dimtion Shaarlier hasta 1.2.2. Ha sido declarada crítica. La función createTag del archivo app/src/main/java/com/dimtion/shaarlier/TagsSource.java del componente Tag Handler es afectada por esta vulnerabilidad. La manipulación conduce a la inyección SQL. La actualización a la versión… | |
| Modificada | Media (6.5) | 1.3% | — | Paloaltonetworks Cortex XsoarFedoraproject Fedora | 8/2/2023 | 17/6/2026 | A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server. | |
| Modificada | Alta (7.5) | 1.4% | — | GNU LessFedoraproject Fedora | 7/2/2023 | 17/6/2026 | In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal. | |
| Modificada | Media (5.4) | 0.56% | — | Pdf.js Viewer Project Pdf.js Viewer | 6/2/2023 | 17/6/2026 | The PDF.js Viewer WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 0.51% | — | 0MK Shortener Project 0MK Shortener | 6/2/2023 | 17/6/2026 | The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the zeromk_options_page function. This makes it possible for unauthenticated attackers to inject malicious web scripts via the 'zeromk_user'… | |
| Modificada | Alta (7.5) | 1.8% | — | Harfbuzz Project HarfbuzzFedoraproject Fedora | 4/2/2023 | 17/6/2026 | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. | |
| Modificada | Crítica (9.8) | 1.00% | — | Json-parser Project Json-parser | 3/2/2023 | 17/6/2026 | Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function. | |
| Modificada | Media (6.5) | 90% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+2 | 3/2/2023 | 17/6/2026 | OpenSSH server (sshd) v9.1 introdujo una vulnerabilidad de doble liberación durante el manejo de "options.key_algorithms". Esto se ha corregido en OpenSSH v9.2. La doble liberación puede ser aprovechada por un atacante remoto no autenticado en la configuración por defecto, para saltar a cualquier ubicación en el… | |
| Modificada | Media (5.5) | 0.25% | — | Pesign Project PesignFedoraproject FedoraRedhat Enterprise Linux | 2/2/2023 | 17/6/2026 | A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This… | |
| Modificada | Alta (8.8) | 0.95% | — | Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+9 | 1/2/2023 | 17/6/2026 | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters | |
| Modificada | Media (5.5) | 0.39% | — | UBI Reader Project UBI Reader | 31/1/2023 | 17/6/2026 | ubireader_extract_files es vulnerable a path traversal cuando se ejecuta contra archivos UBIFS específicamente manipulados, lo que permite al atacante sobrescribir archivos fuera del directorio de extracción (siempre que el proceso tenga acceso de escritura a ese archivo o directorio). Esto se debe al hecho de que un… | |
| Modificada | Media (5.4) | 0.47% | — | PDF Viewer Project PDF Viewer | 30/1/2023 | 17/6/2026 | El complemento PDF Viewer de WordPress anterior a 1.0.0 no valida ni escapa uno de sus atributos de código corto, lo que podría permitir a los usuarios con un rol tan bajo como colaborador realizar un ataque de cross-site scripting almacenado. | |
| Modificada | Media (5.5) | 1.5% | — | GNU TARFedoraproject Fedora | 30/1/2023 | 17/6/2026 | GNU Tar hasta 1.34 tiene una lectura fuera de los límites de un byte que resulta en el uso de memoria no inicializada para un salto condicional. No se ha demostrado explotación para cambiar el flujo de control. El problema ocurre en from_header en list.c a través de un archivo V7 en el que mtime tiene aproximadamente… | |
| Modificada | Media (5.5) | 0.44% | — | GNU BinutilsFedoraproject FedoraRedhat Enterprise Linux | 27/1/2023 | 17/6/2026 | Se encontró una falla de acceso ilegal a la memoria en el paquete binutils. El parseo de un archivo ELF que contiene información de versión de símbolo corrupta puede resultar en una denegación de servicio. Este problema es el resultado de una solución incompleta para CVE-2020-16599. | |
| Modificada | Alta (8.8) | 0.72% | — | WP Topbar Project WP Topbar | 23/1/2023 | 17/6/2026 | Vulnerabilidad de inyección SQL (SQLi) autenticada en versiones WP-TopBar <= 5.36. |