Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 25 respecto a la semana anterior
Críticas / altas1269▼ 244 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
3076 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.26% | — | Proofpoint Threat Response Auto Pull | 14/6/2023 | 17/6/2026 | A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (PTR/TRAP) could allow an authenticated administrator on an adjacent network to replace the image file with an arbitrary MIME type. This could result in arbitrary javascript code execution in an admin… | |
| Modificada | Media (6.5) | 1.0% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Media (6.3) | 0.88% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (7.3) | 1.2% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Media (6.5) | 2.0% | — | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Denial of Service Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 14/6/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 0.63% | — | Sailpoint Identityiq | 5/6/2023 | 17/6/2026 | IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java constructor with no arguments or a Java constructor… | |
| Modificada | Media (4.3) | 0.41% | — | Stormshield Endpoint Security | 31/5/2023 | 17/6/2026 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters. | |
| Modificada | Media (5.5) | 0.15% | — | Stormshield Endpoint Security | 30/5/2023 | 17/6/2026 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information. | |
| Modificada | Alta (8.8) | 0.26% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions. | |
| Modificada | Media (6.1) | 0.57% | — | Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System | 20/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site… | |
| Modificada | Alta (8.8) | 0.34% | — | Cisco Business 140ac Access Point FirmwareCisco Business 141acm FirmwareCisco Business 142acm FirmwareCisco Business 143acm Firmware+4 | 18/5/2023 | 17/6/2026 | A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login implementation. An attacker could exploit… | |
| Modificada | Alta (7.8) | 0.52% | 💥 PoC | Seqrite END Point Security | 11/5/2023 | 17/6/2026 | Incorrect access control in Quick Heal Technologies Limited Seqrite Endpoint Security (EPS) all versions prior to v8.0 allows attackers to escalate privileges to root via supplying a crafted binary to the target system. | |
| Modificada | Alta (8.8) | 0.38% | — | Rockwellautomation Factorytalk Vantagepoint | 11/5/2023 | 17/6/2026 | A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could… | |
| Modificada | Media (5.5) | 0.16% | — | Intel Endpoint Management Assistant | 10/5/2023 | 17/6/2026 | Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.16% | — | Intel Endpoint Management Assistant Configuration ToolIntel Manageability Commander | 10/5/2023 | 17/6/2026 | Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access. | |
| Analizada | Alta (7.2) | 85% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 1.8% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 20h2+10 | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Modificada | Media (6.5) | 67% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (7.5) | 0.70% | — | Agilepoint NX | 8/5/2023 | 17/6/2026 | AgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversal - Vulnerability allows path traversal and downloading files from the server, by an unspecified request. | |
| Modificada | Crítica (9.1) | 0.61% | — | Agilepoint NX | 8/5/2023 | 17/6/2026 | AgilePoint NX v8.0 SU2.2 & SU2.3 – Arbitrary File Delete Vulnerability allows arbitrary file deletion, by an unspecified request. | |
| Modificada | Crítica (9.8) | 0.70% | — | Agilepoint NX | 8/5/2023 | 17/6/2026 | AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request. | |
| Modificada | Alta (8.8) | 0.67% | — | Easyappointments | 15/4/2023 | 17/6/2026 | Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modificada | Media (5.4) | 0.45% | — | Easyappointments | 15/4/2023 | 17/6/2026 | Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modificada | Media (5.4) | 0.47% | — | Easyappointments | 15/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |