Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.39% | — | Netscout Ngeniusone | 7/12/2023 | 17/6/2026 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4). | |
| Modificada | Media (5.4) | 0.39% | — | Netscout Ngeniusone | 7/12/2023 | 17/6/2026 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4). | |
| Modificada | Media (6.1) | 0.41% | — | Netscout Ngeniusone | 7/12/2023 | 17/6/2026 | NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability. | |
| Modificada | Media (5.4) | 0.39% | — | Netscout Ngeniusone | 7/12/2023 | 17/6/2026 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4). | |
| Modificada | Media (5.4) | 0.39% | — | Netscout Ngeniusone | 7/12/2023 | 17/6/2026 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4). | |
| Modificada | Crítica (9.1) | 0.84% | — | Netscout Ngeniuspulse | 7/12/2023 | 17/6/2026 | NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability | |
| Modificada | Crítica (9.8) | 1.5% | — | Netscout Ngeniuspulse | 7/12/2023 | 17/6/2026 | NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability. | |
| Modificada | Crítica (9.8) | 0.71% | — | Netscout Ngeniuspulse | 7/12/2023 | 17/6/2026 | NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. | |
| Modificada | Alta (7.8) | 0.20% | — | Forescout Secureconnector | 3/9/2023 | 17/6/2026 | ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element | |
| Modificada | Alta (8.1) | 0.35% | — | Bluemark Dronescout Ds230 Firmware | 11/7/2023 | 17/6/2026 | DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID… | |
| Modificada | Alta (8.1) | 0.36% | — | Bluemark Dronescout Ds230 Firmware | 11/7/2023 | 17/6/2026 | DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure. Specifically, the firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS endpoint from which the firmware update… | |
| Modificada | Media (6.8) | 0.32% | — | Bluemark Dronescout Ds230 Firmware | 11/7/2023 | 17/6/2026 | DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, at the right times, spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID receiver to drop real… | |
| Modificada | Crítica (9.8) | 0.65% | — | Omicronenergy StationguardOmicronenergy Stationscout | 23/3/2023 | 17/6/2026 | Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions. | |
| Modificada | Crítica (9.8) | 0.59% | — | Omicronenergy StationguardOmicronenergy Stationscout | 23/3/2023 | 17/6/2026 | The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system. | |
| Modificada | Baja (3.5) | 0.32% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required… | |
| Modificada | Baja (3.1) | 0.28% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required… | |
| Modificada | Alta (8.8) | 0.73% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload. | |
| Modificada | Media (6.1) | 0.35% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 6 of 6. | |
| Modificada | Media (6.1) | 0.35% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 5 of 6. | |
| Modificada | Media (6.1) | 0.35% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 4 of 6. | |
| Modificada | Media (6.1) | 0.35% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 3 of 6. | |
| Modificada | Media (6.1) | 0.35% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 2 of 6. | |
| Modificada | Media (6.1) | 0.35% | — | Netscout Ngeniusone | 27/1/2023 | 17/6/2026 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 1 of 6. | |
| Modificada | Crítica (9.8) | 0.64% | — | Cub-scout-tracker Project Cub-scout-tracker | 6/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Seiji42 cub-scout-tracker. This affects an unknown part of the file databaseAccessFunctions.js. The manipulation leads to sql injection. The patch is named b4bc1a328b1f59437db159f9d136d9ed15707e31. It is recommended to apply a patch to fix this issue. The… | |
| Modificada | Media (4.3) | 0.29% | — | Seoscout SEO Scout | 25/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SEO Scout plugin <= 0.9.83 at WordPress allows attackers to trick users with administrative rights to unintentionally change the plugin settings. |