Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
4611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 88% | ⚠ Explotación activa💥 Exploit | Barracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+1 | 24/5/2023 | 17/6/2026 | A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete… | |
| Modificada | Alta (8.8) | 0.26% | — | Winwar WP Email Capture | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | |
| Modificada | Alta (7.8) | 0.70% | — | Dell Vxrail Hyperconverged Infrastructure | 23/5/2023 | 17/6/2026 | Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable… | |
| Modificada | Alta (8.2) | 0.36% | — | Dell Vxrail Hyperconverged Infrastructure | 23/5/2023 | 17/6/2026 | Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the… | |
| Modificada | Crítica (9.8) | 1.3% | — | Microengine Mailform | 23/5/2023 | 17/6/2026 | MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. | |
| Modificada | Crítica (9.8) | 0.92% | — | Microengine Mailform | 23/5/2023 | 17/6/2026 | Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. | |
| Modificada | Crítica (9.8) | 0.97% | — | Clusterlabs PCSRedhat Enterprise Linux High AvailabilityRedhat Enterprise Linux High Availability EUS | 17/5/2023 | 17/6/2026 | It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was… | |
| Modificada | Media (4.3) | 0.37% | — | Jenkins Email Extension | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another user stop watching an attacker-specified job. | |
| Modificada | Media (4.3) | 0.50% | — | Jenkins Email Extension | 16/5/2023 | 17/6/2026 | Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system. | |
| Modificada | Media (5.4) | 0.37% | — | Webfwd Mail Subscribe List | 16/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Richard Leishman t/a Webforward Mail Subscribe List plugin <= 2.1.9 versions. | |
| Modificada | Media (6.1) | 0.48% | — | I13websolution Thumbnail Carousel Slider | 15/5/2023 | 17/6/2026 | The Thumbnail carousel slider WordPress plugin before 1.1.10 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting vulnerability which could be used against high privilege users such as admin. | |
| Modificada | Media (5.5) | 0.17% | — | Intel Retail Edge Program | 10/5/2023 | 17/6/2026 | Improper input validation in the Intel(R) Retail Edge Mobile Android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.17% | — | Intel Retail Edge Program | 10/5/2023 | 17/6/2026 | Improper access control in the Intel(R) Retail Edge android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel Retail Edge Program | 10/5/2023 | 17/6/2026 | Improper access control in the Intel(R) Retail Edge Mobile iOS application before version 3.4.7 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Mass Email TO Users | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Mass Email To users plugin <= 1.1.4 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Cybonet Pineapp Mail Secure | 8/5/2023 | 17/6/2026 | Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint. | |
| Modificada | Alta (7.5) | 0.42% | — | Vk.company Mymail | 7/5/2023 | 17/6/2026 | The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mailbutler Shimo | 4/5/2023 | 17/6/2026 | An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use. | |
| Modificada | Media (4.8) | 0.39% | — | Winwar WP Email Capture | 2/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | |
| Modificada | Media (4.8) | 0.53% | — | Smtp Mailing Queue Project Smtp Mailing Queue | 2/5/2023 | 17/6/2026 | The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.57% | — | Webfwd Mail Subscribe List | 2/5/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, has been found in Mail Subscribe List Plugin up to 2.0.10 on WordPress. This issue affects some unknown processing of the file index.php. The manipulation of the argument sml_name/sml_email leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Media (6.1) | 0.56% | — | Yikesinc Easy Forms FOR Mailchimp | 24/4/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 1.8% | — | Rails-routes-to-json Project Rails-routes-to-json | 24/4/2023 | 17/6/2026 | rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | |
| Modificada | Media (6.1) | 0.51% | — | Eslint-detailed-reporter Project Eslint-detailed-reporter | 20/4/2023 | 17/6/2026 | A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by this issue is the function renderIssue in the library lib/template-generator.js. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The patch… | |
| Modificada | Media (6.1) | 0.60% | — | I13websolution Thumbnail Carousel Slider | 18/4/2023 | 17/6/2026 | The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… |