Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
366 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.33% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 11/10/2023 | 17/6/2026 | BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpicalavailability WP Ical Availability | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP iCal Availability plugin <= 1.0.3 versions. | |
| Modificada | Alta (8.8) | 0.23% | — | Peterbutler Timthumb Vulnerability Scanner | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Peter Butler Timthumb Vulnerability Scanner plugin <= 1.54 versions. | |
| Modificada | Crítica (9.8) | 0.83% | — | IBM Observability With Instana | 4/10/2023 | 17/6/2026 | IBM Observability with Instana 1.0.243 through 1.0.254 could allow an attacker on the network to execute arbitrary code on the host after a successful DNS poisoning attack. IBM X-Force ID: 259789. | |
| Modificada | Alta (7.5) | 0.85% | — | Redhat Network Observability | 15/9/2023 | 17/6/2026 | A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication. | |
| Modificada | Crítica (9.6) | 0.66% | — | Intel Manageability Commander | 11/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter. | |
| Modificada | Media (6.1) | 1.8% | — | Phpjabbers Availability Booking Calendar | 3/8/2023 | 17/6/2026 | A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Media (5.4) | 0.56% | — | Gzscripts Availability Booking Calendar PHP | 27/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible… | |
| Modificada | Media (5.4) | 0.56% | — | Gzscripts Availability Booking Calendar PHP | 27/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The… | |
| Modificada | Media (6.1) | 0.39% | — | Gzscripts Availability Booking Calendar PHP | 7/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site… | |
| Modificada | Crítica (9.8) | 0.97% | — | Clusterlabs PCSRedhat Enterprise Linux High AvailabilityRedhat Enterprise Linux High Availability EUS | 17/5/2023 | 17/6/2026 | It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was… | |
| Modificada | Media (5.5) | 0.16% | — | Intel Endpoint Management Assistant Configuration ToolIntel Manageability Commander | 10/5/2023 | 17/6/2026 | Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.3) | 0.32% | — | Jenkins Neuvector Vulnerability Scanner | 12/4/2023 | 17/6/2026 | Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server. | |
| Modificada | Crítica (9.1) | 8.6% | — | IBM Observability With Instana | 3/3/2023 | 17/6/2026 | Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,… | |
| Modificada | Media (6.5) | 0.41% | — | Hcltechsw Bigfix Insights FOR Vulnerability Remediation | 21/12/2022 | 17/6/2026 | Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access. | |
| Modificada | Media (5.3) | 0.22% | — | Hcltechsw Bigfix Insights FOR Vulnerability Remediation | 21/12/2022 | 17/6/2026 | Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure. This requires privileged network access. | |
| Modificada | Alta (7.8) | 5.8% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. | |
| Modificada | Alta (7.5) | 41% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. | |
| Modificada | Alta (8.8) | 0.47% | — | Intel Active Management Technology Software Development KITIntel Endpoint Management AssistantIntel Manageability Commander | 11/11/2022 | 17/6/2026 | Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (6.5) | 0.42% | — | Intel Killer Wifi SoftwareIntel Proset/wireless WifiIntel Uefi Wifi DriverIntel Killer Wi-fi 6 Ax1650 Firmware+338 | 11/11/2022 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access. |