Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
5112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.46% | — | Sunellsecurity Sn-xvr3804e1 FirmwareSunellsecurity Sn-xvr3808e2 FirmwareSunellsecurity Sn-adr3804e1 FirmwareSunellsecurity Sn-adr3808e1 Firmware+3 | 15/2/2023 | 17/6/2026 | Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request. | |
| Modificada | Media (6.5) | 0.53% | — | Sunellsecurity Sn-xvr3804e1 FirmwareSunellsecurity Sn-xvr3808e2 FirmwareSunellsecurity Sn-adr3804e1 FirmwareSunellsecurity Sn-adr3808e1 Firmware+3 | 15/2/2023 | 17/6/2026 | Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request. | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Defender Security Intelligence Updates | 14/2/2023 | 19/8/2026 | Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | |
| Modificada | Media (5.3) | 0.72% | — | Sonicwall Email Security | 14/2/2023 | 17/6/2026 | SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses. | |
| Modificada | Media (5.3) | 0.44% | — | Dahuasecurity Ipc-hf71242f-z-x FirmwareDahuasecurity Ipc-hf7442f-z-x FirmwareDahuasecurity Ipc-hf7842f-z-x FirmwareDahuasecurity Ipc-hf5241f-ze Firmware+93 | 9/2/2023 | 17/6/2026 | Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a specially crafted packet to the vulnerable interface, an attacker can modify the device system time. | |
| Modificada | Alta (7.8) | 0.26% | — | Elastic EndgameElastic Endpoint Security | 8/2/2023 | 17/6/2026 | An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. | |
| Modificada | Alta (7.4) | 60% | — | OpensslStormshield Management CenterStormshield Network Security | 8/2/2023 | 17/6/2026 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by… | |
| Modificada | Alta (7.5) | 20% | — | OpensslStormshield Network Security | 8/2/2023 | 17/6/2026 | The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is… | |
| Modificada | Media (5.9) | 16% | 💥 PoC | OpensslStormshield Endpoint SecurityStormshield SslvpnStormshield Network Security | 8/2/2023 | 17/6/2026 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The… | |
| Modificada | Alta (8.8) | 18% | — | Siteground Security | 6/2/2023 | 17/6/2026 | The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue. | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+9 | 1/2/2023 | 17/6/2026 | On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.… | |
| Modificada | Alta (7.5) | 1.5% | — | F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security Manager | 1/2/2023 | 17/6/2026 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+9 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, and BIG-IP SPK starting in version 1.6.0, when a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 17.0.x before 17.0.0.2 and 16.1.x before 16.1.3.3, when a HTTP profile with the non-default Enforcement options of Enforce HTTP Compliance and Unknown Methods: Reject are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note:… | |
| Modificada | Media (6.1) | 0.35% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open… | |
| Modificada | Alta (8.5) | 73% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | Existe una vulnerabilidad de cadena de formato en iControl SOAP que permite a un atacante autenticado bloquear el proceso CGI de iControl SOAP o, potencialmente, ejecutar código arbitrario. En el modo de dispositivo BIG-IP, una explotación exitosa de esta vulnerabilidad puede permitir al atacante cruzar un límite de… | |
| Modificada | Alta (7.5) | 0.63% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Modificada | Media (4.9) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an… | |
| Modificada | Alta (7.5) | 0.66% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when OCSP authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have… | |
| Modificada | Media (5.9) | 0.53% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 1/2/2023 | 17/6/2026 | In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to the BIG-IP system can cause the Traffic Management… | |
| Modificada | Alta (7.8) | 0.35% | — | Toshiba Storage Security Software | 31/1/2023 | 17/6/2026 | La vulnerabilidad de autenticación incorrecta en Toshiba Storage Security Software V1.2.0.7413 permite obtener información confidencial a través del módulo de autenticación de contraseña (local). | |
| Modificada | Alta (8.3) | 0.14% | — | Schneider-electric Ecostruxure Cybersecurity Admin Expert | 30/1/2023 | 17/6/2026 | Existe una vulnerabilidad CWE-295: validación de certificado incorrecta que podría provocar que el software CAE proporcione datos incorrectos a los usuarios finales cuando utilizan CAE para configurar dispositivos. Además, las credenciales podrían filtrarse, lo que permitiría a un atacante iniciar sesión en la… | |
| Modificada | Alta (8.1) | 0.31% | — | Schneider-electric Ecostruxure Cybersecurity Admin Expert | 30/1/2023 | 17/6/2026 | Existe una vulnerabilidad CWE-290: omisión de autenticación mediante suplantación de identidad que podría bloquear el acceso de los usuarios legítimos a los dispositivos o facilitar la creación de cuentas de puerta trasera al suplantar un dispositivo en la red local. Productos afectados: EcoStruxure? Cybersecurity… | |
| Modificada | Alta (8.8) | 0.19% | — | HP Security Manager | 30/1/2023 | 17/6/2026 | Se han identificado posibles vulnerabilidades en HP Security Manager que pueden permitir la escalada de privilegios, la ejecución de código arbitrario y la divulgación de información. |