Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
325 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.36% | — | Bracketspace Advanced Cron ManagerAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BracketSpace Advanced Cron Manager – debug & control allows Stored XSS.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.2. | |
| Analizada | Alta (8.1) | 0.17% | — | Johnbillion WP Crontrol | 25/3/2024 | 17/6/2026 | WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative users to create events in the WP-Cron system that store and execute PHP code subject to the restrictive security permissions documented here. While there is no known vulnerability in this feature on… | |
| Analizada | Media (5.4) | 0.33% | — | Acronis Cyber Protect | 27/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. | |
| Analizada | Media (6.1) | 0.30% | — | Acronis Cyber Protect | 27/2/2024 | 17/6/2026 | Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. | |
| Analizada | Media (5.5) | 0.17% | — | Acronis Cyber Protect | 27/2/2024 | 17/6/2026 | Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391. | |
| Analizada | Media (5.4) | 0.26% | — | Acronis Cyber Protect | 27/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. | |
| Analizada | Media (5.5) | 0.16% | — | Acronis Cyber Protect | 27/2/2024 | 17/6/2026 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. | |
| Modificada | Alta (7.8) | 0.26% | — | Objectcomputing Micronaut | 9/2/2024 | 17/6/2026 | Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are susceptible to drive-by localhost attacks. While not typical of a production… | |
| Analizada | Alta (7.1) | 0.21% | — | Acronis Agent | 14/12/2023 | 17/6/2026 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36943. | |
| Modificada | Alta (7.8) | 0.25% | — | Acronis Cyber Protect Home Office | 12/12/2023 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40901, Acronis Cyber Protect Cloud Agent (Windows) before build 39378, Acronis Cyber Protect 16 (Windows) before build 39938, Acronis True Image OEM (Windows)… | |
| Modificada | Alta (7.5) | 0.61% | — | Advanced Export Products Orders Cron CSV Excel Project Advanced Export Products Orders Cron CSV Excel | 7/11/2023 | 17/6/2026 | Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table. | |
| Modificada | Media (6.5) | 0.53% | — | Objectcomputing Micronaut Security | 9/10/2023 | 17/6/2026 | Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC setup using Micronaut where multiple OIDC… | |
| Modificada | Alta (7.3) | 0.24% | — | Acronis Agent | 9/10/2023 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36497, Acronis Cyber Protect 16 (Windows) before build 37391. | |
| Modificada | Alta (7.1) | 0.21% | — | Acronis Agent | 9/10/2023 | 17/6/2026 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36497, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169. | |
| Modificada | Alta (7.1) | 0.24% | — | Acronis Agent | 6/10/2023 | 17/6/2026 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36343, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169. | |
| Modificada | Media (5.5) | 0.26% | — | Acronis Agent | 6/10/2023 | 17/6/2026 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 36119. | |
| Modificada | Alta (7.1) | 0.24% | — | Acronis Agent | 6/10/2023 | 17/6/2026 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 37391. | |
| Modificada | Media (5.5) | 0.29% | — | Acronis Agent | 5/10/2023 | 17/6/2026 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | |
| Modificada | Media (5.5) | 0.17% | — | Acronis Agent | 5/10/2023 | 17/6/2026 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | |
| Modificada | Media (5.5) | 0.18% | — | Acronis Agent | 5/10/2023 | 17/6/2026 | Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35739, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 37391. | |
| Modificada | Media (5.5) | 0.17% | — | Acronis Agent | 5/10/2023 | 17/6/2026 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35739. | |
| Modificada | Media (5.5) | 0.17% | — | Acronis Agent | 5/10/2023 | 17/6/2026 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35739. | |
| Modificada | Media (5.5) | 0.18% | — | Acronis Agent | 5/10/2023 | 17/6/2026 | Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 35739, Acronis Cyber Protect 16 (Windows) before build 37391. | |
| Modificada | Alta (7.1) | 0.36% | — | Acronis Agent | 5/10/2023 | 17/6/2026 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 31477. | |
| Modificada | Alta (7.1) | 0.35% | — | Acronis Agent | 5/10/2023 | 17/6/2026 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 31637, Acronis Cyber Protect 16 (Linux, Windows) before build 37391. |