Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
5112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.55% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 2/8/2023 | 17/6/2026 | Un atacante autenticado con privilegios de invitado o superior puede provocar la finalización del proceso iControl SOAP mediante el envío de solicitudes no reveladas. Nota: No se evalúan las versiones de software que han alcanzado el fin del soporte técnico (EoTS). | |
| Modificada | Media (6.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 2/8/2023 | 17/6/2026 | Existe una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en una página no revelada de la utilidad de configuración de BIG-IP que permite a un atacante ejecutar JavaScript en el contexto del usuario actualmente conectado. Nota: No se evalúan las versiones de software que han alcanzado el fin del soporte ténico… | |
| Modificada | Alta (8.8) | 1.3% | — | IBM Security Verify Governance | 31/7/2023 | 17/6/2026 | IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 257873. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Security Verify Governance | 31/7/2023 | 17/6/2026 | IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257772. | |
| Modificada | Alta (7.5) | 0.90% | — | Owasp Modsecurity | 26/7/2023 | 17/6/2026 | Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity. | |
| Modificada | Alta (7.8) | 5.7% | — | Checkpoint Endpoint Security | 23/7/2023 | 17/6/2026 | Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | Dahuasecurity Smart Parking Management | 22/7/2023 | 17/6/2026 | A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has… | |
| Modificada | Media (6.5) | 0.73% | — | Netentsec Application Security Gateway | 20/7/2023 | 17/6/2026 | A vulnerability was found in Beijing Netcon NS-ASG 6.3. It has been classified as problematic. This affects an unknown part of the file /admin/test_status.php. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is… | |
| Modificada | Crítica (9.8) | 4.0% | 💥 PoC | Vmware Spring Security | 19/7/2023 | 17/6/2026 | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass. | |
| Modificada | Alta (7.8) | 0.17% | — | IBM Security Guardium | 19/7/2023 | 17/6/2026 | IBM Security Guardium v11.3 podría permitir a un usuario local escalar sus privilegios debido a controles de permisos inadecuados. ID de IBM X-Force: 240908. | |
| Modificada | Media (6.5) | 0.71% | — | IBM Security Guardium | 19/7/2023 | 17/6/2026 | IBM Security Guardium v11.3 podría permitir a un usuario autenticado provocar una denegación de servicio debido a una incorrecta validación de entrada. ID de IBM X-Force: 240903. | |
| Modificada | Media (5.4) | 0.43% | — | IBM Security Verify Access | 19/7/2023 | 17/6/2026 | IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would… | |
| Modificada | Baja (3.7) | 1.5% | — | Debian LinuxOracle GraalvmOracle Graalvm FOR JDKOracle JDK+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u371, 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle… | |
| Modificada | Baja (3.7) | 1.3% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371, 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM… | |
| Modificada | Media (5.1) | 0.48% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for… | |
| Modificada | Baja (3.7) | 1.3% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Utility). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and… | |
| Modificada | Baja (3.1) | 0.95% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7… | |
| Modificada | Media (5.3) | 0.66% | 💥 PoC | Vmware Spring Security | 18/7/2023 | 17/6/2026 | Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s DispatcherServlet. (DispatcherServlet is a Spring MVC component that… | |
| Modificada | Media (6.5) | 0.40% | — | Watchguard Panda Security VPN | 13/7/2023 | 17/6/2026 | Una vulnerabilidad de secuestro de DLL en Panda Security VPN para Windows anterior a la versión v15.14.8 permite a los atacantes ejecutar código arbitrario mediante la colocación de un archivo DLL manipulado en el mismo directorio que "PANDAVPN.exe". | |
| Modificada | Media (5.5) | 0.78% | 💥 Exploit | Keepersecurity KeeperKeepersecurity Keeperfill | 12/7/2023 | 17/6/2026 | An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 (fixed in 17.2), allows local attackers to gain sensitive information via plaintext password storage in memory after the user is already logged in, and may persist after… | |
| Modificada | Media (4.3) | 0.56% | — | Wpmudev Defender Security | 12/7/2023 | 17/6/2026 | The Defender Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.6. This is due to missing or incorrect nonce validation on the verify_otp_login_time() function. This makes it possible for unauthenticated attackers to verify a one time login via a forged… | |
| Modificada | Media (4.9) | 0.47% | — | SAP ERP Defense Forces AND Public Security | 11/7/2023 | 17/6/2026 | While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog… | |
| Modificada | Media (6.1) | 0.60% | — | Phpgurukul Online Security Guards Hiring System | 10/7/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box. | |
| Modificada | Alta (8.8) | 0.94% | — | Trellix Enterprise Security Manager | 3/7/2023 | 17/6/2026 | A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain… | |
| Modificada | Alta (7.8) | 0.47% | — | Trellix Enterprise Security Manager | 3/7/2023 | 17/6/2026 | An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of privilege escalation or to execute arbitrary commands. |