Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2834▲ 81 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

3325 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.64%—Esri Arcgis Server21/7/202317/6/2026
There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux platforms that may allow a remote, unauthenticated attacker to create crafted content which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Mitigation:…
ModificadaBaja (3.4)0.48%—Esri Arcgis Server21/7/202317/6/2026
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser. The privileges required to execute this attack are high.
AnalizadaAlta (8.4)0.99%—Esri Portal FOR Arcgis21/7/202317/6/2026
There is a Cross‑Site Scripting (XSS) vulnerability in Esri ArcGIS Enterprise Sites versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which, when clicked by a victim, could result in the execution of arbitrary JavaScript code in the target’s browser. Exploitation requires…
AnalizadaMedia (5.4)0.44%—Esri Portal FOR Arcgis21/7/202317/6/2026
There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack…
AnalizadaAlta (8.4)0.86%—Esri Portal FOR Arcgis21/7/202317/6/2026
There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS Sites versions 11.1 and below that may allow a remote, authenticated attacker with high‑privileged access to create a crafted link that is persisted within the site configuration. When accessed by a victim, the stored payload may…
ModificadaAlta (7)0.18%—Esri Arcgis Insights19/7/202317/6/2026
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires…
ModificadaAlta (7.5)0.67%—Esri Arcgis Insights19/7/202317/6/2026
There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires…
ModificadaAlta (7.5)1.4%—Tp-link Archer C2 V1 FirmwareTp-link Archer C20 FirmwareTp-link Archer C50 Firmware18/7/20239/7/2026
TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.
ModificadaAlta (8.8)0.26%—Woocommerce Order Barcodes17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions.
ModificadaMedia (5.4)0.36%—Nesote Inout Search Engine AI Edition16/7/202317/6/2026
A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this…
ModificadaMedia (5.5)0.19%—Archerirm Archer14/7/202317/6/2026
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files.
ModificadaMedia (5.4)0.51%—Archerirm Archer14/7/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.
ModificadaAlta (8)0.38%—Archerirm Archer14/7/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.
ModificadaMedia (6.5)0.48%—Archerirm Archer14/7/202317/6/2026
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication.
ModificadaMedia (6.5)0.58%—Archerirm Archer14/7/202317/6/2026
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
ModificadaCrítica (9.8)40%💥 ExploitArcserve UDP3/7/202317/6/2026
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as…
ModificadaMedia (4.3)0.39%—Webberzone Better Search1/7/202317/6/2026
El plugin Better Search para WordPress es vulnerable a ataques de tipo Cross-Site Request Forgery (CSRF) en versiones hasta la 2.5.2 inclusive. Esto se debe a la falta o incorrecta validación nonce en las funciones "bsearch_process_settings_import()" y "bsearch_process_settings_export()". Esto hace posible que…
ModificadaAlta (7.8)0.21%—Samsung Searchwidget28/6/202317/6/2026
Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.
ModificadaAlta (7.8)0.24%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1327/6/202317/6/2026
A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.24%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1327/6/202317/6/2026
A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.
ModificadaAlta (7.8)0.25%—Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+1323/6/202317/6/2026
A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities. Exploitation of this vulnerability may lead to code execution.
ModificadaMedia (6.1)0.66%—Techsneeze Dmarc Report22/6/202317/6/2026
Cross site scripting (XSS) vulnerabiliy in dmarcts-report-viewer dashboard versions 1.1 and thru commit 8a1d882b4c481a05e296e9b38a7961e912146a0f, allows unauthenticated attackers to execute arbitrary code via the org_name or domain values.
ModificadaAlta (7.8)0.16%—IBM Spectrum Protect Backup-archive Client22/6/202317/6/2026
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls.
ModificadaAlta (8.8)0.97%—Sugarcrm17/6/202317/6/2026
Se ha descubierto un problema en SugarCRM Enterprise antes de v11.0.6 y v12.x antes de v12.0.3. Se han identificado dos vectores de inyección SQL en la API REST. Mediante el uso de peticiones manipuladas, código SQL personalizado puede ser inyectado a través de la API REST debido a la falta de validación de entrada.…
ModificadaAlta (7.2)1.2%—Sugarcrm17/6/202317/6/2026
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been identified in the DocuSign module. By using crafted requests, custom PHP code can be injected and executed through the DocuSign module because of missing input validation.…