Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2780▲ 24 respecto a la semana anterior
Críticas / altas1288▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.1) | 1.0% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Pluggable Auth). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con pocos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… | |
| Modificada | Media (4.9) | 1.3% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Optimizer). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… | |
| Modificada | Baja (2.7) | 0.94% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Security: Privileges). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los… | |
| Modificada | Media (4.4) | 1.2% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: InnoDB). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con altos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques exitosos de esta… | |
| Modificada | Media (4.9) | 1.3% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: InnoDB). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad fácilmente explotable permite a un atacante con altos privilegios con acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques exitosos de… | |
| Modificada | Media (4.4) | 1.3% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Replication). Las versiones afectadas son 8.0.33 y anteriores. Una vulnerabilidad difícil de explotar permite a un atacante con altos privilegios y acceso a la red a través de múltiples protocolos comprometer MySQL Server. Los ataques… | |
| Modificada | Media (6.5) | 2.4% | — | Rockwellautomation Thinmanager | 18/7/2023 | 17/6/2026 | An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal vulnerability exists that allows a remote actor to leverage the privileges of… | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Kinetix 5700 Firmware | 18/7/2023 | 17/6/2026 | The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if impacted by this vulnerability, which prohibits operational capabilities of the device resulting in a denial-of-service attack. | |
| Modificada | Media (5.3) | 0.46% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 17/7/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380. | |
| Modificada | Media (5.3) | 0.71% | — | IBM Infosphere Information Server | 17/7/2023 | 17/6/2026 | IBM InfoSphere Information Server v11.7 podría permitir a un atacante remoto obtener información del sistema utilizando una consulta especialmente manipulada que podría ayudar en futuros ataques contra el sistema. ID de IBM X-Force: 257695. | |
| Modificada | Crítica (9.8) | 0.49% | — | Oretnom23 Lost AND Found Information System | 15/7/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. This affects an unknown part of the file /classes/Master.php?f=save_item of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the… | |
| Modificada | Crítica (9.8) | 0.49% | — | Oretnom23 Lost AND Found Information System | 15/7/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=save_inquiry of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection.… | |
| Modificada | Alta (7.5) | 3.7% | — | Rockwellautomation 1756-en4tr FirmwareRockwellautomation 1756-en4trk FirmwareRockwellautomation 1756-en4trxt Firmware | 12/7/2023 | 17/6/2026 | Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages. | |
| Modificada | Crítica (9.8) | 5.5% | — | Rockwellautomation 1756-en2f Series A FirmwareRockwellautomation 1756-en2f Series B FirmwareRockwellautomation 1756-en2f Series C FirmwareRockwellautomation 1756-en2t Series A Firmware+8 | 12/7/2023 | 17/6/2026 | Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and… | |
| Modificada | Crítica (9.6) | 0.66% | — | Rockwellautomation Enhanced HIM | 11/7/2023 | 17/6/2026 | The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross-Origin Resource Sharing (CORS) settings and, as a result, is vulnerable to a Cross Site Request Forgery (CSRF) attack. To exploit this vulnerability, a malicious user… | |
| Modificada | Alta (8.8) | 0.93% | — | Rockwellautomation Powermonitor 1000 Firmware | 11/7/2023 | 17/6/2026 | The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote… | |
| Modificada | Crítica (9.8) | 3.8% | 💥 Exploit | Oretnom23 Lost AND Found Information System | 28/6/2023 | 17/6/2026 | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information. | |
| Modificada | Media (5.5) | 0.17% | — | IBM Robotic Process Automation | 27/6/2023 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to insufficient security configuration which may allow creation of namespaces within a cluster. IBM X-Force ID: 244500. | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Robotic Process Automation | 27/6/2023 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3 is vulnerable to security misconfiguration of the Redis container which may provide elevated privileges. IBM X-Force ID: 244074. | |
| Modificada | Alta (7.5) | 0.39% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144. | |
| Modificada | Media (4.3) | 0.44% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134. | |
| Modificada | Media (6.5) | 0.63% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403. | |
| Modificada | Media (6.1) | 0.48% | — | IBM Cloud PAK FOR Business Automation | 27/6/2023 | 17/6/2026 | IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 255587. | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Factorytalk Transaction Manager | 13/6/2023 | 17/6/2026 | A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage condition, causing intermittent application… |