Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 79 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.52% | — | Iscute Cute Http File Server | 3/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Cute Http File Server 2.0. This affects an unknown part of the component Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (4.3) | 0.47% | — | Discourse | 28/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, information about restricted-visibility topic tags could be obtained by unauthorized users. The issue is patched in version 3.0.6 of the `stable` branch and… | |
| Modificada | Alta (7.5) | 0.64% | — | Discourse | 28/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, in multiple controller actions, Discourse accepts limit params but does not impose any upper bound on the values being accepted. Without an upper bound, the… | |
| Modificada | Media (6.5) | 0.70% | — | Discourse | 28/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can prevent the defer queue from proceeding promptly on sites hosted in the same multisite installation. The issue is patched in version… | |
| Modificada | Media (4.3) | 0.54% | — | Discourse | 28/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a malicious user can edit a post in a topic and cause a DoS with a carefully crafted edit reason. The issue is patched in version 3.0.6 of the `stable`… | |
| Modificada | Baja (3.1) | 0.27% | — | Discourse | 28/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passed` branches, more users than permitted could be created from invite links. The issue is patched in version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the… | |
| Modificada | Media (5.4) | 0.36% | — | Discourse | 28/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous (i.e. unauthenticated) users. There are… | |
| Modificada | Media (6.1) | 0.65% | — | Netdisco | 26/7/2023 | 17/6/2026 | Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links. | |
| Modificada | Media (4.8) | 0.63% | — | Netdisco | 26/7/2023 | 17/6/2026 | Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/TypeAhead.pm. | |
| Modificada | Alta (7.5) | 0.70% | — | Discourse | 14/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Modificada | Media (4.3) | 0.40% | — | Discourse | 14/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The issue is patched in the latest stable, beta and tests-passed version of Discourse. | |
| Modificada | Alta (7.5) | 0.71% | — | Cisco Cjose | 14/7/2023 | 17/6/2026 | OpenIDC/cjose es una biblioteca C que implementa Javascript Object Signing and Encryption (JOSE). La rutina de descifrado AES GCM utiliza incorrectamente la longitud de la etiqueta de la etiqueta de autenticación real proporcionada en el JWE. La especificación dice que se debe aplicar una longitud fija de 16 octetos.… | |
| Modificada | Media (6.1) | 0.40% | — | Discourse | 13/7/2023 | 17/6/2026 | Discourse is an open source discussion platform. A CSP (Content Security Policy) nonce reuse vulnerability could allow XSS attacks to bypass CSP protection. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack to completely bypass CSP. The… | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Alta (7.4) | 0.34% | — | Cisco Nx-os | 12/7/2023 | 17/6/2026 | A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers that are used by the… | |
| Modificada | Media (4.3) | 0.39% | — | Cisco Webex Meetings | 7/7/2023 | 17/6/2026 | A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web interface on an affected system. An attacker could exploit… | |
| Modificada | Media (5.4) | 0.64% | — | Cisco Webex Meetings | 7/7/2023 | 17/6/2026 | A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email… | |
| Modificada | Crítica (9.8) | 46% | 💥 Exploit | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 29/6/2023 | 17/6/2026 | The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for… | |
| Modificada | Media (6.1) | 0.54% | — | Projectdiscovery Interactsh | 28/6/2023 | 17/6/2026 | Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for a specific subdomain, i.e `app.` Interactsh server used to create cname entries for `app` pointing to `projectdiscovery.github.io` as… | |
| Modificada | Media (6.6) | 0.29% | — | Cisco DUO | 28/6/2023 | 17/6/2026 | A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication and access an affected macOS device. This vulnerability is due to the incorrect handling of responses from Cisco Duo when the application is configured to fail open. An… | |
| Modificada | Alta (7.7) | 0.66% | — | Cisco Telepresence Video Communication Server | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway… | |
| Modificada | Media (4.8) | 0.48% | — | Cisco Sf200-24 FirmwareCisco Sf200-24fp FirmwareCisco Sf200-24p FirmwareCisco Sf200-48 Firmware+57 | 28/6/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack… | |
| Modificada | Media (6.5) | 0.52% | — | Cisco Secure Workload | 28/6/2023 | 17/6/2026 | A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials. This vulnerability is due to improper role-based access… | |
| Modificada | Media (6.1) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Media (6.1) | 0.51% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This… |