Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1970 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.81% | — | Kodcloud Kodexplorer | 6/9/2023 | 17/6/2026 | A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page. | |
| Modificada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+13 | 28/8/2023 | 17/6/2026 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and… | |
| Modificada | Media (4.9) | 0.75% | — | Fit2cloud Cloudexplorer Lite | 24/8/2023 | 17/6/2026 | Cloud Explorer Lite is an open source cloud management platform. Prior to version 1.4.0, there is a risk of sensitive information leakage in the user information acquisition of CloudExplorer Lite. The vulnerability has been fixed in version 1.4.0. | |
| Modificada | Alta (7.5) | 1.8% | — | Libbitcoin Explorer | 9/8/2023 | 17/6/2026 | The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settings. This allows remote attackers to recover any wallet private keys generated… | |
| Modificada | Crítica (9.8) | 3.4% | — | Fit2cloud Cloudexplorer Lite | 4/8/2023 | 17/6/2026 | CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from upgrading. | |
| Modificada | Media (5.4) | 0.57% | — | Wifi File Explorer Project Wifi File Explorer | 20/7/2023 | 17/6/2026 | A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Media (6.1) | 0.73% | — | Kodcloud Kodexplorer | 10/7/2023 | 17/6/2026 | KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field. | |
| Modificada | Crítica (9.8) | 0.46% | — | Fit2cloud Cloudexplorer Lite | 27/6/2023 | 17/6/2026 | Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of cloudexplorer-lite prior to 1.2.0 did not enforce strong passwords. This… | |
| Modificada | Media (4.8) | 0.44% | — | Codecolorer Project Codecolorer | 27/6/2023 | 17/6/2026 | The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.78% | — | Fit2cloud Cloudexplorer Lite | 27/6/2023 | 17/6/2026 | Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0. | |
| Modificada | Alta (8.8) | 1.1% | — | Progress OpenedgeProgress Openedge ExplorerProgress Openedge Management | 23/6/2023 | 17/6/2026 | In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through… | |
| Modificada | Media (4.3) | 0.38% | — | Fit2cloud Cloudexplorer | 26/5/2023 | 17/6/2026 | CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organization in CloudExplorer Lite. This is due to a missing permission check on the user profile. It is recommended to upgrade the version to v1.1.0. There are no known workarounds for this vulnerability. | |
| Modificada | Media (4.3) | 0.38% | — | Fit2cloud Cloudexplorer | 26/5/2023 | 17/6/2026 | CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organization/workspace permissions are not properly checked. This allows users to add themselves to any organization. This vulnerability has been fixed in v1.1.0. Users are advised to upgrade. There are… | |
| Modificada | Alta (8.1) | 0.66% | — | Fit2cloud Cloudexplorer Lite | 23/5/2023 | 17/6/2026 | Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | |
| Modificada | Media (4.9) | 0.68% | — | Fit2cloud Cloudexplorer Lite | 23/5/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | |
| Modificada | Crítica (9.8) | 0.58% | — | Worksmobile Drive Explorer | 23/5/2023 | 17/6/2026 | Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is required to execute LINE WORKS Drive… | |
| Modificada | Alta (8.8) | 1.1% | — | Extplorer | 12/5/2023 | 17/6/2026 | eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions. | |
| Modificada | Media (4.9) | 3.0% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 26/4/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint. | |
| Modificada | Alta (8.8) | 2.7% | — | Kodcloud Kodexplorer | 22/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (8.8) | 2.4% | — | Extplorer | 21/3/2023 | 17/6/2026 | Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent | |
| Modificada | Media (5.5) | 0.24% | — | Tgsoft Vir.it ExplorerTgsoft Viragtlt.sys | 13/3/2023 | 17/6/2026 | A vulnerability was found in TG Soft Vir.IT eXplorer 9.4.86.0. It has been rated as problematic. This issue affects the function 0x82730088 in the library VIRAGTLT.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been… | |
| Modificada | Alta (7.5) | 34% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 6/3/2023 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS). | |
| Modificada | Media (6.5) | 6.3% | — | Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 6/3/2023 | 17/6/2026 | ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports. | |
| Modificada | Alta (7.5) | 1.1% | — | Hitachienergy Sys600 FirmwareHitachienergy Rtu500 FirmwareHitachienergy Reb500 FirmwareHitachienergy Pwc600 Firmware+9 | 21/2/2023 | 17/6/2026 | A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products. An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections. Already… | |
| Modificada | Media (6.1) | 2.6% | — | Zohocorp Manageengine Assetexplorer | 1/2/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation. |