Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 18 respecto a la semana anterior
Críticas / altas1271▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
3326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 1.2% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability… | |
| Modificada | Alta (7.4) | 1.3% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows… | |
| Analizada | Media (4.3) | 0.88% | — | Gatsbyjs Gatsby-plugin-sharp | 17/4/2023 | 29/9/2026 | gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing library. The gatsby-plugin-sharp plugin prior to versions 5.8.1 and 4.25.1 contains a path traversal vulnerability exposed when running the Gatsby develop server (`gatsby develop`). It should be noted… | |
| Modificada | Alta (8.8) | 0.73% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 15/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /admin/maintenance/view_designation.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is… | |
| Modificada | Media (4.8) | 0.39% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 7/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.1.1 versions. | |
| Modificada | Alta (7.5) | 0.87% | — | Cisco Packet Data Network Gateway | 5/4/2023 | 17/6/2026 | A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection. This vulnerability is due to the VPP improperly handling a malformed packet. An attacker could exploit this… | |
| Modificada | Crítica (9.6) | 0.67% | — | Netgate PfsenseNetgate Pfsense Acme Package | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Red-gate SQL Monitor | 4/4/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter. | |
| Modificada | Media (5.4) | 0.46% | — | Jenkins Pipeline Aggregator View | 2/4/2023 | 17/6/2026 | Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission. | |
| Modificada | Alta (7.5) | 0.62% | — | Devolutions Gateway | 2/4/2023 | 17/6/2026 | Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable. | |
| Modificada | Alta (8.8) | 0.58% | — | Red-gate SQL Monitor | 30/3/2023 | 17/6/2026 | Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges. | |
| Modificada | Crítica (9.1) | 3.4% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation… | |
| Modificada | Crítica (9.8) | 3.4% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation… | |
| Modificada | Media (6.1) | 0.35% | — | Forcepoint Cloud Security GatewayForcepoint WEB Security | 29/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_submit.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_submit.mhtml modules) allows Reflected… | |
| Modificada | Media (6.1) | 0.35% | — | Forcepoint Cloud Security GatewayForcepoint WEB Security | 29/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_form.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_form.mhtml modules) allows Reflected… | |
| Modificada | Media (6.1) | 0.35% | — | Forcepoint Cloud Security GatewayForcepoint WEB Security | 29/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud (login_reset_request.mhtml modules), Forcepoint Web Security Portal on Hybrid (login_reset_request.mhtml modules)… | |
| Modificada | Crítica (9.8) | 9.8% | 💥 Exploit | Netgate Pfsense PlusPfsense | 22/3/2023 | 17/6/2026 | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests. | |
| Modificada | Alta (8.8) | 90% | 💥 Exploit | Netgate Pfsense | 17/3/2023 | 17/6/2026 | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml. | |
| Modificada | Crítica (9.8) | 0.84% | — | Ubikasec Waap CloudUbikasec Waap Gateway | 8/3/2023 | 17/6/2026 | In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Stagil Navigation | 28/2/2023 | 17/6/2026 | An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system. | |
| Modificada | Alta (7.5) | 47% | 💥 Exploit | Stagil Navigation | 28/2/2023 | 17/6/2026 | An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system. | |
| Modificada | Media (4.8) | 0.46% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 27/2/2023 | 17/6/2026 | The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Crítica (9.8) | 12% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. |