Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

366 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)0.33%—Hcltech Bigfix Insights FOR Vulnerability Remediation11/10/202317/6/2026
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (8.8)0.25%—Wpicalavailability WP Ical Availability10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP iCal Availability plugin <= 1.0.3 versions.
ModificadaAlta (8.8)0.23%—Peterbutler Timthumb Vulnerability Scanner9/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Peter Butler Timthumb Vulnerability Scanner plugin <= 1.54 versions.
ModificadaCrítica (9.8)0.83%—IBM Observability With Instana4/10/202317/6/2026
IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789.
ModificadaAlta (7.5)0.85%—Redhat Network Observability15/9/202317/6/2026
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.
ModificadaCrítica (9.6)0.66%—Intel Manageability Commander11/8/202317/6/2026
Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaCrítica (9.8)0.89%—Phpjabbers Availability Booking Calendar4/8/202317/6/2026
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change.
ModificadaCrítica (9.8)0.89%—Phpjabbers Availability Booking Calendar4/8/202317/6/2026
PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.
ModificadaCrítica (9.8)0.89%—Phpjabbers Availability Booking Calendar4/8/202317/6/2026
PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.
ModificadaMedia (6.1)1.8%—Phpjabbers Availability Booking Calendar3/8/202317/6/2026
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The…
ModificadaMedia (5.4)0.56%—Gzscripts Availability Booking Calendar PHP27/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible…
ModificadaMedia (5.4)0.56%—Gzscripts Availability Booking Calendar PHP27/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The…
ModificadaMedia (6.1)0.39%—Gzscripts Availability Booking Calendar PHP7/7/202317/6/2026
A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site…
ModificadaCrítica (9.8)0.97%—Clusterlabs PCSRedhat Enterprise Linux High AvailabilityRedhat Enterprise Linux High Availability EUS17/5/202317/6/2026
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was…
ModificadaMedia (5.5)0.16%—Intel Endpoint Management Assistant Configuration ToolIntel Manageability Commander10/5/202317/6/2026
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.3)0.32%—Jenkins Neuvector Vulnerability Scanner12/4/202317/6/2026
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.
ModificadaCrítica (9.1)8.6%—IBM Observability With Instana3/3/202317/6/2026
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.
AnalizadaCrítica (9.8)100%⚠ Explotación activaZohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+1818/1/202331/7/2026
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,…
ModificadaMedia (6.5)0.41%—Hcltechsw Bigfix Insights FOR Vulnerability Remediation21/12/202217/6/2026
Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access.
ModificadaMedia (5.3)0.22%—Hcltechsw Bigfix Insights FOR Vulnerability Remediation21/12/202217/6/2026
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure. This requires privileged network access.
ModificadaAlta (7.8)5.8%—Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+1323/11/202217/6/2026
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
ModificadaAlta (7.5)41%—Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+1323/11/202217/6/2026
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault.
ModificadaAlta (8.8)0.47%—Intel Active Management Technology Software Development KITIntel Endpoint Management AssistantIntel Manageability Commander11/11/202217/6/2026
Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.
ModificadaMedia (6.5)0.42%—Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+33811/11/202217/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access.