Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.29% | — | Loxone Miniserver GO GEN 2 Firmware | 5/7/2023 | 17/6/2026 | The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password and escalate privileges. | |
| Modificada | Alta (7.2) | 1.4% | — | Loxone Miniserver GO GEN 2 Firmware | 5/7/2023 | 17/6/2026 | The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter. | |
| Modificada | Media (4.3) | 0.39% | — | Amministrazione Trasparente Project Amministrazione Trasparente | 1/7/2023 | 17/6/2026 | The Amministrazione Trasparente plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1. This is due to missing or incorrect nonce validation on the at_save_aturl_meta() function. This makes it possible for unauthenticated attackers to update meta data via a forged… | |
| Modificada | Alta (7.5) | 0.50% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Alta (7.2) | 1.3% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. | |
| Modificada | Alta (8.1) | 0.55% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. | |
| Modificada | Alta (7.8) | 0.68% | — | Malwarebytes Binisoft Windows Firewall Control | 26/6/2023 | 17/6/2026 | Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password." | |
| Modificada | Alta (7.1) | 0.30% | — | Opentext Archive Center Administration | 24/5/2023 | 17/6/2026 | The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft… | |
| Modificada | Alta (7.5) | 1.8% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. | |
| Modificada | Crítica (9.8) | 0.92% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data… | |
| Modificada | Media (5.3) | 2.5% | — | Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython | 19/4/2023 | 17/6/2026 | The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after… | |
| Modificada | Media (6.5) | 0.33% | — | Inisev Redirection | 17/4/2023 | 17/6/2026 | The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack. | |
| Modificada | Media (5.4) | 0.60% | — | SAS WEB Administration Interface | 3/4/2023 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is SAS Web Administration interface (SASAdmin). For the product… | |
| Modificada | Media (6.5) | 0.34% | — | Inisev Redirection | 3/4/2023 | 17/6/2026 | The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack. | |
| Modificada | Alta (7.5) | 20% | 💥 PoC | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+2 | 17/2/2023 | 17/6/2026 | An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. | |
| Modificada | Alta (7.8) | 0.17% | — | Administrative Tools FOR Intel Network AdaptersIntel Non-volatile Memory Update Utility | 16/2/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Administrative Tools FOR Intel Network Adapters | 16/2/2023 | 17/6/2026 | Insufficient control flow management in some Intel(R) Ethernet Controller Administrative Tools drivers for Windows before version 1.5.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Media (6.5) | 90% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+2 | 3/2/2023 | 17/6/2026 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states… | |
| Modificada | Alta (8.8) | 0.83% | — | 202-ecommerce Administrative Mandate | 2/2/2023 | 9/7/2026 | PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Openmanage Server Administrator | 1/2/2023 | 17/6/2026 | Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with elevated privileges. Exploitation… | |
| Modificada | Media (6.1) | 0.51% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application | |
| Modificada | Media (6.1) | 0.51% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses. |