Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.53% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set. | |
| Aplazada | Media (5.9) | 0.28% | — | Erez Hadas-sonnenschein Smartarget Message BARAI | 2/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Message Bar smartarget-message-bar.This issue affects Smartarget Message Bar: from n/a through <= 1.5. | |
| Aplazada | Media (5.3) | 0.31% | — | Wordplus BP Better MessagesAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Better Messages: from n/a through 2.4.32. | |
| Aplazada | Media (6.5) | 0.16% | — | Tibco HawkAITibco Enterprise Message ServiceAI | 15/5/2024 | 17/6/2026 | Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files. | |
| Aplazada | Media (4.3) | 0.24% | — | Divspot DS Site MessageAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in divSpot DS Site Message.This issue affects DS Site Message: from n/a through 1.14.4. | |
| Aplazada | Alta (7.8) | 1.2% | — | Amazon Sagemaker-python-sdkAI | 3/5/2024 | 17/6/2026 | sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected versions the capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module allows for potentially unsafe Operating System (OS) Command Injection if inappropriate… | |
| Aplazada | Alta (7.8) | 0.41% | — | Amazon Sagemaker-python-sdkAI | 3/5/2024 | 17/6/2026 | sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted data is passed as pickled object arrays. This consequently may allow an… | |
| Aplazada | Alta (7.4) | 0.71% | — | Honeywell GCL MessageAI | 11/4/2024 | 17/6/2026 | Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and… | |
| Analizada | Alta (7.8) | 0.18% | — | Sagemcom F@st 3686 Firmware | 14/3/2024 | 17/6/2026 | Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without requiring login credentials. This vulnerability is possible because the 'Login.asp and logout.asp' files do not handle session details… | |
| Modificada | Alta (7.8) | 0.17% | — | Intel System Usage Report | 14/2/2024 | 17/6/2026 | Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.33% | — | Intel System Usage Report FOR Gameplay | 14/2/2024 | 17/6/2026 | Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Modificada | Media (6.7) | 0.19% | — | Intel System Usage Report FOR Gameplay | 14/2/2024 | 17/6/2026 | Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.8) | 0.41% | — | Wso2 API ManagerWso2 API Manager AnalyticsWso2 API MicrogatewayWso2 Data Analytics Server+5 | 18/12/2023 | 17/6/2026 | Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console. | |
| Modificada | Media (5.4) | 0.39% | — | Wordplus Better Messages | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPlus Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss allows Stored XSS.This issue affects Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member,… | |
| Modificada | Media (5.3) | 1.1% | — | Systematica Financial CalculatorSystematica FIX AdapterSystematica Http AdapterSystematica Mssql Messagebus Proxy+2 | 30/11/2023 | 17/6/2026 | Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15),… | |
| Modificada | Media (6.5) | 0.79% | — | Gopiplus Message Ticker | 31/10/2023 | 17/6/2026 | The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with… | |
| Modificada | Media (4.3) | 1.5% | 💥 PoC | Vmware Spring Advanced Message Queuing Protocol | 19/10/2023 | 17/6/2026 | In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized.… | |
| Modificada | Alta (8.8) | 0.21% | — | Arulprasadj Publish Confirm Message | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Publish Confirm Message plugin <= 1.3.1 versions. | |
| Modificada | Crítica (9.8) | 0.45% | — | Sage 200 Spain | 4/10/2023 | 17/6/2026 | Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution of MS SQL commands and escalate… | |
| Modificada | Crítica (9.8) | 0.82% | — | Sagernet Sing-box | 25/9/2023 | 17/6/2026 | Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to… | |
| Modificada | Alta (7.5) | 1.4% | — | O-ran-sc RIC Message Router | 1/9/2023 | 17/6/2026 | O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device. | |
| Modificada | Alta (7.5) | 2.1% | — | O-ran-sc RIC Message Router | 28/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component. | |
| Modificada | Alta (7.5) | 2.2% | — | O-ran-sc RIC Message Router | 28/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet. | |
| Modificada | Alta (8.8) | 0.53% | — | SAP Message Server | 8/8/2023 | 17/6/2026 | The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious user to enter the network of the SAP… | |
| Modificada | Media (5.4) | 0.35% | — | Sage X3 | 22/6/2023 | 9/7/2026 | Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those… |