Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
3326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.1% | 💥 Exploit | Buildagate Project Buildagate | 11/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL. | |
| Modificada | Media (6.1) | 81% | 💥 Exploit | Citrix GatewayCitrix Application Delivery Controller | 10/7/2023 | 17/6/2026 | Los productos ADC y Gateway de Citrix son vulnerables a ataques de tipo Cross-Site Scripting (XSS). | |
| Modificada | Alta (7.5) | 1.1% | — | Citrix Application Delivery ControllerCitrix Gateway | 10/7/2023 | 17/6/2026 | Arbitrary file read in Citrix ADC and Citrix Gateway | |
| Modificada | Media (6.1) | 0.55% | — | Webdevstudios WDS Multisite Aggregate | 10/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in WDS Multisite Aggregate Plugin up to 1.0.0 on WordPress. Affected is the function update_options of the file includes/WDS_Multisite_Aggregate_Options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely.… | |
| Modificada | Crítica (9.8) | 1.1% | — | Miniorange Web3 - Crypto Wallet Login & NFT Token Gating | 30/6/2023 | 17/6/2026 | The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user… | |
| Modificada | Media (6.1) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Media (6.1) | 0.51% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This… | |
| Modificada | Media (5.4) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Alta (8.8) | 0.39% | — | Silabs Z/ip Gateway SDK | 21/6/2023 | 17/6/2026 | Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.25% | — | Silabs Z/ip Gateway SDK | 21/6/2023 | 17/6/2026 | A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered. | |
| Modificada | Media (6.8) | 0.27% | — | Silabs Z/ip Gateway SDK | 21/6/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a Z-Wave controller device to overwrite global memory and potentially execute arbitrary code. | |
| Modificada | Baja (3.5) | 0.25% | — | Silabs Z/ip Gateway SDK | 21/6/2023 | 17/6/2026 | A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an authenticated attacker within Z-Wave range to manipulate an array pointer to disclose the contents of global memory. | |
| Modificada | Crítica (9.8) | 0.64% | — | Siren Investigate | 19/6/2023 | 17/6/2026 | En Siren Investigate anterior a la versión 13.2.2, las claves de sesión permanecen activas incluso después de cerrar la sesión. | |
| Modificada | Alta (7.5) | 1.2% | — | Woocommerce Stripe Payment Gateway | 14/6/2023 | 17/6/2026 | Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions. | |
| Modificada | Media (5.5) | 0.20% | — | Yandex Navigator | 9/6/2023 | 17/6/2026 | Un problema detectado en Yandex Navigator v6.60 para Android permite a aplicaciones no autorizadas provocar una denegación de servicio persistente mediante la manipulación de los archivos "SharedPreference". | |
| Modificada | Alta (7.8) | 0.36% | — | Yandex Navigator | 9/6/2023 | 17/6/2026 | An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. | |
| Modificada | Media (6.1) | 0.68% | — | Vadesecure Secure Gateway | 9/6/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via the username, password, and language cookies parameter. | |
| Modificada | Media (6.1) | 0.68% | — | Vadesecure Secure Gateway | 9/6/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ directory. | |
| Modificada | Media (6.1) | 0.88% | — | Vadesecure Secure Gateway | 9/6/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the X-Rewrite-URL parameter. | |
| Modificada | Media (5.3) | 0.91% | — | Gatsbyjs Gatsby | 8/6/2023 | 17/6/2026 | Gatsby is a free and open source framework based on React. The Gatsby framework prior to versions 4.25.7 and 5.9.1 contain a Local File Inclusion vulnerability in the `__file-code-frame` and `__original-stack-frame` paths, exposed when running the Gatsby develop server (`gatsby develop`). Any file in scope of the… | |
| Modificada | Media (5.3) | 0.59% | — | Trianglemicroworks Scada Data Gateway | 7/6/2023 | 17/6/2026 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker… | |
| Modificada | Crítica (9.8) | 0.71% | — | Trianglemicroworks Scada Data Gateway | 7/6/2023 | 17/6/2026 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly… | |
| Modificada | Media (6.5) | 0.34% | — | Dell Secure Connect Gateway | 1/6/2023 | 17/6/2026 | Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text. | |
| Modificada | Alta (8.1) | 0.47% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability. | |
| Modificada | Media (5.4) | 0.34% | — | Broadcom Advanced Secure GatewayBroadcom Content Analysis | 1/6/2023 | 17/6/2026 | Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability. |