Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.7) | 0.54% | — | Redhat Data GridRedhat Jboss Data GridInfinispan | 18/12/2023 | 17/6/2026 | A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration. | |
| Modificada | Media (6.5) | 1.1% | — | Redhat Data GridRedhat Jboss Data GridInfinispan | 18/12/2023 | 17/6/2026 | A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service. | |
| Modificada | Media (6.5) | 0.72% | — | Redhat Data GridRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformInfinispan | 18/12/2023 | 17/6/2026 | A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions. | |
| Modificada | Media (6.5) | 0.80% | — | Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Data GridInfinispan | 18/12/2023 | 17/6/2026 | A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions. | |
| Modificada | Media (4.8) | 0.42% | — | Amministrazione Trasparente Project Amministrazione Trasparente | 25/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi Amministrazione Trasparente plugin <= 8.0.2 versions. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell EMC Openmanage Server Administrator | 13/10/2023 | 17/6/2026 | Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the system. Exploitation may lead to a complete system… | |
| Modificada | Crítica (9.8) | 0.63% | — | Turnatasarim Advertising Administration Panel | 6/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising Administration Panel allows SQL Injection. This issue affects Advertising Administration Panel: before 1.1. | |
| Modificada | Alta (7.4) | 0.55% | — | Redhat Data GridInfinispan HOT ROD | 4/10/2023 | 17/6/2026 | A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Media (5.5) | 0.18% | — | Hitachi OPS Center Administrator | 3/10/2023 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00. | |
| Modificada | Crítica (9.8) | 0.67% | — | MRV Logging Administration Panel | 27/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 . | |
| Modificada | Crítica (9.8) | 0.62% | — | Osoft Dyeing - Printing - Finishing Production Management | 5/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1. | |
| Modificada | Alta (7.5) | 1.5% | — | Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+1 | 31/8/2023 | 17/6/2026 | A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest… | |
| Modificada | Media (5.5) | 0.64% | — | GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. | |
| Modificada | Media (5.5) | 0.61% | — | GNU BinutilsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. | |
| Modificada | Media (6.1) | 0.35% | — | Genesys Administrator Extension | 13/8/2023 | 17/6/2026 | Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261. | |
| Modificada | Crítica (9.8) | 0.63% | — | Farmakom Remote Administration Console | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02. | |
| Modificada | Crítica (9.8) | 3.5% | 💥 Exploit | Wifi-soft Unibox Administration | 31/7/2023 | 17/6/2026 | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page. | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Analizada | Crítica (9.8) | 0.57% | — | CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+4 | 25/7/2023 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of… | |
| Modificada | Media (6) | 0.21% | — | Oracle Hyperion Essbase Administration Services | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion… | |
| Modificada | Alta (7.5) | 2.0% | — | ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+2 | 17/7/2023 | 17/6/2026 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | |
| Modificada | Media (5.3) | 0.62% | — | OpensslManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration Utility | 14/7/2023 | 17/6/2026 | Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding… | |
| Modificada | Alta (7.8) | 0.32% | — | Loxone Miniserver GO GEN 2 Firmware | 5/7/2023 | 17/6/2026 | Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo configuration. This allows the elevated execution of binaries without a password requirement. |