Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2766▲ 12 respecto a la semana anterior
Críticas / altas1276▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
–

4643 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.57%—CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+425/7/202317/6/2026
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of…
ModificadaCrítica (9.8)3.9%💥 ExploitAvaya Aura Device Services19/7/202317/6/2026
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
ModificadaMedia (5.3)0.51%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK19/7/202317/6/2026
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosing server version information which may be used to determine software vulnerabilities at the operating system level. IBM X-Force ID: 259368.
ModificadaMedia (4.3)0.45%—Oracle Self-service Human Resources18/7/202317/6/2026
Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workforce Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human…
ModificadaMedia (6)0.21%—Oracle Hyperion Essbase Administration Services18/7/202317/6/2026
Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion…
ModificadaMedia (5.3)0.46%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK17/7/202317/6/2026
IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380.
ModificadaCrítica (9.8)0.50%—Oretnom23 AC Repair AND Services System15/7/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_inquiry of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql…
ModificadaMedia (5.3)0.62%—OpensslManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration Utility14/7/202317/6/2026
Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding…
ModificadaCrítica (9.8)0.54%—Oretnom23 AC Repair AND Services System13/7/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The associated…
ModificadaMedia (6.1)0.39%—Oretnom23 AC Repair AND Services System13/7/202317/6/2026
A vulnerability has been found in SourceCodester AC Repair and Services System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=user/manage_user. The manipulation of the argument firstname/middlename leads to cross site scripting. The attack can be…
ModificadaCrítica (9.8)0.54%—Oretnom23 AC Repair AND Services System13/7/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester AC Repair and Services System 1.0. Affected is an unknown function of the file Master.php?f=delete_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the…
ModificadaCrítica (9.8)0.54%—Oretnom23 AC Repair AND Services System13/7/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be…
ModificadaCrítica (9.8)0.49%—Oretnom23 Service Provider Management System12/7/202317/6/2026
Se ha encontrado una vulnerabilidad en SourceCodester Service Provider Management System v1.0. Se ha declarado como crítica. Esta vulnerabilidad afecta a código desconocido del archivo "/classes/Master.php?f=save_inquiry". La manipulación del argumento id conduce a una inyección sql. El ataque puede iniciarse de forma…
ModificadaMedia (6)0.20%—Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+1212/7/202317/6/2026
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected…
ModificadaMedia (6.5)0.69%—Microsoft Azure Service Fabric11/7/202317/6/2026
Azure Service Fabric on Windows Information Disclosure Vulnerability
ModificadaCrítica (9.8)0.49%—Oretnom23 AC Repair AND Services System11/7/202317/6/2026
A vulnerability was found in SourceCodester AC Repair and Services System 1.0 and classified as critical. This issue affects some unknown processing of the file Master.php?f=save_service of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated…
ModificadaMedia (5.4)3.5%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus7/7/202317/6/2026
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
ModificadaMedia (6.1)0.39%—Servicenow6/7/202317/6/2026
ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Layout. This vulnerability would enable an authenticated user to inject arbitrary scripts.
ModificadaAlta (7.5)0.93%—Cisco Unified Communications Manager IM AND Presence Service28/6/202317/6/2026
A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to cause a temporary service outage for all Cisco Unified CM IM&P users who are attempting to authenticate to the service,…
ModificadaAlta (7.5)0.50%—Apereo Central Authentication Service27/6/202317/6/2026
Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When checking the validity of the provided…
ModificadaCrítica (9.8)0.73%—Palantir Clips2Palantir Video Clip DistributorPalantir Video History Service26/6/202317/6/2026
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete…
ModificadaCrítica (9.8)6.0%💥 PoCZohocorp Manageengine Adselfservice Plus20/6/202317/6/2026
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail…
ModificadaMedia (5.4)0.54%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/6/202317/6/2026
Las versiones 6.5.16.0 (y anteriores) de Adobe Experience Manager se ven afectadas por una vulnerabilidad de Cross-Site Scripting (XSS) Reflejado. Si un atacante con pocos privilegios es capaz de convencer a una víctima para que visite una URL que haga referencia a una página vulnerable, se puede ejecutar contenido…
ModificadaMedia (5.4)0.51%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/6/202317/6/2026
Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.51%—Adobe Experience ManagerAdobe Experience Manager Cloud Service15/6/202317/6/2026
Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.