Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2837▲ 84 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
3325 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Sugarcrm | 17/6/2023 | 17/6/2026 | An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the REST API. By using a crafted request, custom PHP code can be injected through the REST API because of missing input validation. Regular user privileges can be used to… | |
| Modificada | Alta (8.8) | 1.3% | — | Sugarcrm | 17/6/2023 | 17/6/2026 | An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using crafted requests, custom PHP code can be injected and executed through the Notes module because of missing input validation. Regular user… | |
| Modificada | Crítica (9.8) | 1.4% | — | Tp-link Archer Ax10 Firmware | 16/6/2023 | 9/7/2026 | TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Cdata ARC | 16/6/2023 | 17/6/2026 | CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF). | |
| Modificada | Media (6.1) | 0.34% | — | Faceted Search Project Faceted Search | 16/6/2023 | 17/6/2026 | The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed data. | |
| Modificada | Crítica (9.1) | 0.90% | — | Microfocus Arcsight Logger | 13/6/2023 | 17/6/2026 | Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0. | |
| Modificada | Media (6.1) | 0.47% | — | Microfocus Arcsight Logger | 13/6/2023 | 17/6/2026 | Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0 | |
| Modificada | Media (4.4) | 0.54% | — | Advanced-woo-search Advanced WOO Search | 9/6/2023 | 17/6/2026 | The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (4.4) | 0.56% | — | Fibosearch | 9/6/2023 | 17/6/2026 | The FiboSearch - AJAX Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.23.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions… | |
| Modificada | Alta (8.8) | 1.3% | — | Xforwoocommerce ADD Product TabsXforwoocommerce Autopilot SEOXforwoocommerce Bulk ADD TO CartXforwoocommerce Comment AND Review Spam Control+12 | 7/6/2023 | 17/6/2026 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various versions listed below. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to read, edit, or… | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Media (4.3) | 0.46% | — | Webberzone Better Search | 7/6/2023 | 17/6/2026 | The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to import settings via forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Modificada | Media (4.3) | 0.70% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls. | |
| Modificada | Alta (8.8) | 1.2% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to update arbitrary options on the site. | |
| Modificada | Media (5.3) | 0.85% | — | Eyecix Jobsearch WP JOB Board | 7/6/2023 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin. | |
| Modificada | Media (6.1) | 0.62% | — | Local Service Search Engine Management System Project Local Service Search Engine Management System | 31/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input… | |
| Modificada | Media (5.3) | 0.19% | — | Libarchive | 29/5/2023 | 17/6/2026 | Libarchive hasta la versión 3.6.2 puede hacer que los directorios tengan permisos de escritura global. La llamada "umask()" dentro del archivo "archive_write_disk_posix.c" cambia la máscara de usuario de todo el proceso durante un periodo de tiempo muy corto; una condición de carrera con otro hilo puede llevar a un… | |
| Modificada | Alta (7.1) | 0.30% | — | Opentext Archive Center Administration | 24/5/2023 | 17/6/2026 | The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft… | |
| Modificada | Alta (8.8) | 0.26% | 💥 PoC | Internet-formation Wp-advanced-search | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Archivist Project Archivist | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions. | |
| Modificada | Media (6.7) | 1.8% | 💥 PoC | Tp-link Archer Vr1600v Firmware | 19/5/2023 | 17/6/2026 | A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1.0. 0.9.1 v5006.0 Build 220518 Rel.32480n which allows remote attackers, authenticated to the administrative web portal as an administrator user to open an operating system level… | |
| Modificada | Baja (3.3) | 0.49% | — | Microsoft Azure ARC Jumpstart | 18/5/2023 | 17/6/2026 | Azure Arc Jumpstart Information Disclosure Vulnerability | |
| Modificada | Media (4.8) | 0.37% | — | Webhammer WP Custom Fields Search | 18/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Tychesoftwares Arconix Shortcodes | 16/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Arconix Shortcodes plugin <= 2.1.7 versions. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Prestashop Possearchproducts | 12/5/2023 | 17/6/2026 | Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). |