Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 12 respecto a la semana anterior
Críticas / altas1272▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
3076 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.50% | — | Easyappointments | 15/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modificada | Media (6.5) | 4.1% | 💥 Exploit | Securepoint Unified Threat Management | 12/4/2023 | 17/6/2026 | An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Securepoint Unified Threat Management | 12/4/2023 | 17/6/2026 | An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface. | |
| Modificada | Alta (8.1) | 6.2% | 💥 Exploit | Microsoft Sharepoint FoundationMicrosoft Sharepoint Server | 11/4/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Crítica (9.8) | 1.0% | — | Codepeople CP Appointment Calendar | 10/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to initiate the attack… | |
| Modificada | Media (4.8) | 0.51% | — | Pinpoint Booking System | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.2.8 versions. | |
| Modificada | Media (6.1) | 0.55% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 31/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as problematic. Affected by this issue is the function get_scale of the file Master.php. The manipulation of the argument perc leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.74% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 31/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Grade Point Average GPA Calculator 1.0 and classified as critical. Affected by this vulnerability is the function get_scale of the file Master.php. The manipulation of the argument perc leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.64% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 31/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page with the input php://filter/read=convert.base64-encode/resource=grade_table leads to information… | |
| Modificada | Media (6.1) | 0.55% | — | Grade Point Average (gpa) Calculator Project Grade Point Average (gpa) Calculator | 30/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Grade Point Average GPA Calculator 1.0. This affects an unknown part of the file index.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.1) | 0.35% | — | Forcepoint Cloud Security GatewayForcepoint WEB Security | 29/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_submit.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_submit.mhtml modules) allows Reflected… | |
| Modificada | Media (6.1) | 0.35% | — | Forcepoint Cloud Security GatewayForcepoint WEB Security | 29/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_form.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_form.mhtml modules) allows Reflected… | |
| Modificada | Media (6.1) | 0.35% | — | Forcepoint Cloud Security GatewayForcepoint WEB Security | 29/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_reset_request.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_reset_request.mhtml modules)… | |
| Modificada | Media (6.7) | 0.24% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator… | |
| Modificada | Media (5.5) | 0.26% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE | 23/3/2023 | 17/6/2026 | A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this… | |
| Modificada | Media (6.8) | 0.20% | — | Trendmicro Trend Micro Endpoint Encryption | 22/3/2023 | 17/6/2026 | A vulnerability in Trend Micro Endpoint Encryption Full Disk Encryption version 6.0.0.3204 and below could allow an attacker with physical access to an affected device to bypass Microsoft Windows� Secure Boot process in an attempt to execute other attacks to obtain access to the contents of the device. An attacker… | |
| Modificada | Baja (3.1) | 0.60% | — | Microsoft Sharepoint FoundationMicrosoft Sharepoint Server | 14/3/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Baja (3.8) | 0.43% | — | Easyappointments | 13/3/2023 | 17/6/2026 | Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modificada | Crítica (9.8) | 0.74% | — | Easyappointments | 8/3/2023 | 17/6/2026 | Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modificada | Crítica (9.8) | 0.74% | 💥 PoC | Proofpoint Enterprise Protection | 8/3/2023 | 17/6/2026 | The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and… | |
| Modificada | Alta (8.8) | 0.74% | 💥 PoC | Proofpoint Enterprise Protection | 8/3/2023 | 17/6/2026 | The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below. | |
| Modificada | Media (5.3) | 7.0% | 💥 PoC | Cisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.… | |
| Modificada | Crítica (9.8) | 29% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+1 | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability… | |
| Modificada | Alta (7.1) | 0.15% | — | Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+1 | 28/2/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,… | |
| Modificada | Alta (8.8) | 0.73% | — | Doctors Appointment System Project Doctors Appointment System | 27/2/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Doctors Appointment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/patient.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The attack can be… |