Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

523 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.42%—Buddyboss Buddypress Global Search25/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BuddyBoss BuddyPress Global Search plugin <= 1.2.1 versions.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (5.4)0.37%—Buddyboss3/10/202317/6/2026
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.
ModificadaMedia (5.4)0.42%—Buddyboss3/10/202317/6/2026
Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when the associated image is loaded.
ModificadaMedia (5.4)0.36%—Buddyboss3/10/202317/6/2026
Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).
ModificadaMedia (5.5)0.16%—Redhat Jboss A-mqRedhat Jboss MiddlewareRedhat Openshift Container Platform27/9/202317/6/2026
A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
ModificadaMedia (5.5)0.25%—Redhat Jboss A-mqRedhat Jboss MiddlewareRedhat Openshift Container Platform27/9/202317/6/2026
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
ModificadaAlta (7.5)2.7%—Redhat UndertowRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM LinuxoneRedhat Openshift Container Platform FOR Power+327/9/202317/6/2026
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by…
ModificadaAlta (8.1)1.4%—QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+820/9/20234/8/2026
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and…
ModificadaAlta (7.5)1.8%—Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+1214/9/202317/6/2026
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
ModificadaAlta (8.8)1.0%—Redhat Decision ManagerRedhat DroolsRedhat Jboss Middleware Text-only AdvisoriesRedhat Process Automation11/9/202317/6/2026
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
ModificadaMedia (5.4)0.33%—Webboss.io CMS3/8/202317/6/2026
WebBoss.io CMS v3.7.0.1 contains a stored cross-site scripting (XSS) vulnerability.
ModificadaMedia (5.4)0.33%—Webboss.io CMS3/8/202317/6/2026
WebBoss.io CMS v3.7.0.1 contains a stored Cross-Site Scripting (XSS) vulnerability due to lack of input validation and output encoding.
ModificadaCrítica (9.8)0.79%—Bbossgroups Bboss28/7/202317/6/2026
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.
ModificadaAlta (7.5)0.58%—Webboss.io CMS21/7/202317/6/2026
An access control issue in WebBoss.io CMS v3.7.0.1 allows attackers to access the Website Backup Tool via a crafted GET request.
ModificadaMedia (6.1)0.47%—Webboss.io CMS21/7/202317/6/2026
WebBoss.io CMS before v3.7.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
ModificadaCrítica (9.8)75%💥 ExploitCarel Boss Mini Firmware12/7/202317/6/2026
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
ModificadaMedia (6.5)0.43%—Redhat Build OF QuarkusRedhat Jboss A-mqRedhat KeycloakRedhat Migration Toolkit FOR Runtimes+126/5/202317/6/2026
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the…
ModificadaCrítica (9.8)0.62%—Cityboss E-municipality24/5/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection. This issue affects E-municipality: before 6.05.
ModificadaAlta (7.5)0.60%—Redhat Build OF QuarkusRedhat Integration Camel FOR Spring BootRedhat Integration Camel KRedhat Integration Service Registry+623/2/202317/6/2026
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
ModificadaMedia (6.8)0.23%—Deyeinverter Inverter FirmwareRevolt-power Inverter FirmwareBosswerk Inverter Firmware13/2/202317/6/2026
A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation with the input 12345678 leads to use of hard-coded password. It is possible to…
ModificadaAlta (7.4)0.58%—Redhat Wildfly ElytronRedhat Jboss Enterprise Application Platform13/1/202317/6/2026
wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an…
ModificadaMedia (6.5)0.29%—Bosscms28/11/202217/6/2026
Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.
ModificadaCrítica (9.9)0.82%—Carel Boss Mini Firmware18/11/202217/6/2026
Carel Boss Mini 1.5.0 has Improper Access Control.
ModificadaAlta (7.5)0.86%—Redhat WildflyRedhat AMQRedhat AMQ OnlineRedhat Integration Camel K+413/9/202217/6/2026
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Orbitaley — Vulnerabilidades