Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▲ 64 respecto a la semana anterior
Críticas / altas1288▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
3076 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.36% | — | Phpscriptpoint Bloodbank | 23/7/2023 | 17/6/2026 | A vulnerability was found in phpscriptpoint BloodBank 1.1. It has been rated as problematic. This issue affects some unknown processing of the file page.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235205 was assigned to this vulnerability. NOTE: The… | |
| Modificada | Alta (7.8) | 5.7% | — | Checkpoint Endpoint Security | 23/7/2023 | 17/6/2026 | Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file | |
| Modificada | Alta (7.8) | 0.21% | — | Pointware Easyinventory | 23/7/2023 | 17/6/2026 | A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:\Program Files (x86)\EasyInventory\Easy2W.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-235193 was assigned to… | |
| Modificada | Alta (7.5) | 2.2% | — | Ivanti Endpoint Manager | 21/7/2023 | 17/6/2026 | An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above. | |
| Modificada | Alta (8.8) | 0.26% | — | Easy-appointments Easy Appointments | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nikola Loncar Easy Appointments plugin <= 3.11.9 versions. | |
| Modificada | Media (4.3) | 0.44% | — | Easyappointments | 17/7/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modificada | Alta (7.5) | 1.1% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.8) | 4.3% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 1.3% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 38% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 2.6% | — | Microsoft Sharepoint Server | 11/7/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Media (6.1) | 0.38% | — | Gzscripts PHP GZ Appointment Scheduling Script | 10/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in GZ Scripts PHP GZ Appointment Scheduling Script 1.8. Affected by this vulnerability is an unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be… | |
| Modificada | Crítica (9.8) | 13% | 💥 Exploit | Ivanti Endpoint Manager | 1/7/2023 | 17/6/2026 | A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution. | |
| Modificada | Crítica (9.8) | 3.1% | — | Ivanti Endpoint Manager | 1/7/2023 | 17/6/2026 | A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to… | |
| Modificada | Media (5.5) | 0.28% | — | Malwarebytes Endpoint Detection AND ResponseMalwarebytes | 30/6/2023 | 17/6/2026 | In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier. | |
| Modificada | Alta (7.8) | 0.31% | — | Malwarebytes Endpoint Detection AND ResponseMalwarebytes | 30/6/2023 | 17/6/2026 | The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger. | |
| Modificada | Media (4.3) | 0.39% | — | Stormshield Endpoint Security | 27/6/2023 | 17/6/2026 | Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators. | |
| Modificada | Media (5.5) | 0.19% | — | Stormshield Endpoint Security | 27/6/2023 | 17/6/2026 | Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges. | |
| Modificada | Media (4.3) | 0.25% | — | Proofpoint Insider Threat Management Server | 27/6/2023 | 17/6/2026 | A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected. | |
| Modificada | Media (6.5) | 0.31% | — | Proofpoint Insider Threat Management Server | 27/6/2023 | 17/6/2026 | A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before… | |
| Modificada | Media (4.6) | 0.24% | — | Proofpoint Insider Threat Management Server | 27/6/2023 | 17/6/2026 | A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected. | |
| Modificada | Media (5.5) | 0.15% | — | Proofpoint Insider Threat Management | 27/6/2023 | 17/6/2026 | An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffected. | |
| Modificada | Crítica (9.8) | 0.51% | — | Forcepoint Email SecurityForcepoint WEB Security | 15/6/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection. | |
| Modificada | Alta (7.8) | 0.15% | — | Eset Cyber SecurityEset Endpoint AntivirusEset Server Security | 15/6/2023 | 17/6/2026 | During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product installed, it was possible for a user with lower privileges due to improper privilege management to trigger actions with root privileges. ESET remedied this possible attack… | |
| Modificada | Media (6.8) | 0.25% | — | Proofpoint Threat Response Auto Pull | 14/6/2023 | 17/6/2026 | An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could… |