Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 119 respecto a la semana anterior
Críticas / altas1267▼ 261 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

4321 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/20235/8/2026
Unauthenticated remote code execution
ModificadaMedia (6.5)0.96%—Weave Gitops Terraform Controller14/7/202317/6/2026
Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave GitOps Terraform Controller which could allow an authenticated remote attacker to view sensitive information. This vulnerability stems from…
ModificadaMedia (6)0.20%—Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+1212/7/202317/6/2026
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected…
ModificadaMedia (6.1)0.60%—Instareza Mail Control12/7/202317/6/2026
The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaCrítica (9.8)0.56%—Johnsoncontrols Istar Ultra FirmwareJohnsoncontrols Istar Ultra LT FirmwareJohnsoncontrols Istar Ultra G2 FirmwareJohnsoncontrols Edge G2 Firmware11/7/202317/6/2026
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitCitrix Sharefile Storage Zones Controller10/7/202317/6/2026
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
ModificadaMedia (6.1)81%💥 ExploitCitrix GatewayCitrix Application Delivery Controller10/7/202317/6/2026
Los productos ADC y Gateway de Citrix son vulnerables a ataques de tipo Cross-Site Scripting (XSS).
ModificadaAlta (7.5)1.1%—Citrix Application Delivery ControllerCitrix Gateway10/7/202317/6/2026
Arbitrary file read in Citrix ADC and Citrix Gateway
ModificadaMedia (6.1)1.3%💥 ExploitHestiacp Control Panel30/6/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
ModificadaAlta (7.8)0.68%—Malwarebytes Binisoft Windows Firewall Control26/6/202317/6/2026
Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."
ModificadaMedia (4.8)0.39%—Plainware Shiftcontroller26/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Plainware ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.
ModificadaMedia (4.8)0.45%—Gbcom LAC WEB Control Center22/6/202317/6/2026
Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device.
ModificadaAlta (7.8)0.16%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services14/6/202317/6/2026
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver.
ModificadaAlta (7.8)0.19%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services14/6/202317/6/2026
A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModificadaAlta (7.5)0.88%—Synology Diskstation Manager Unified ControllerSynology Router ManagerSynology Diskstation Manager13/6/202317/6/2026
Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.
ModificadaAlta (8.1)0.97%—Synology Diskstation Manager Unified ControllerSynology Router ManagerSynology Diskstation Manager13/6/202317/6/2026
La vulnerabilidad del elemento de ruta de búsqueda no controlada en la funcionalidad de administración de copias de seguridad en Synology DiskStation Manager (DSM) anterior a 6.2.4-25556-8, 7.0.1-42218-7 y 7.1-42661 permite que usuarios remotos autenticados con privilegios de administrador lean o escriban archivos…
ModificadaAlta (7.1)0.44%—Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux9/6/202317/6/2026
A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.
ModificadaMedia (6.1)0.43%—Plainware Shiftcontroller9/6/202317/6/2026
The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the query string in versions up to, and including, 4.9.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaCrítica (9.8)0.67%—Johnsoncontrols Illustra PRO GEN 4 Dome FirmwareJohnsoncontrols Illustra PRO GEN 4 PTZ Firmware8/6/202317/6/2026
A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.
ModificadaAlta (8.8)1.3%—Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+127/6/202317/6/2026
Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or…
ModificadaAlta (8.8)1.2%—Wpruby Controlled Admin Access7/6/202317/6/2026
The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.
ModificadaCrítica (9.8)0.50%—Gallagher Controller 6000 Firmware1/6/202317/6/2026
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and prior.
ModificadaAlta (7.8)1.4%💥 PoCLinux KernelNetapp HCI Baseboard Management Controller1/6/202317/6/2026
Se encontró una falla en el código de registro de búfer fijo para io_uring (io_sqe_buffer_register en io_uring/rsrc.c) en el kernel de Linux que permite el acceso fuera de los límites a la memoria física más allá del final del búfer. Esta falla permite la escalada completa de privilegios locales.
ModificadaMedia (6.5)0.52%—Johnsoncontrols Openblue Enterprise Manager Data Collector18/5/202317/6/2026
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
ModificadaAlta (7.5)1.1%💥 PoCJohnsoncontrols Openblue Enterprise Manager Data Collector18/5/202317/6/2026
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
Orbitaley — Vulnerabilidades