Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.95% | — | Perforce Helix Core | 8/11/2023 | 17/6/2026 | In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner. | |
| Modificada | Alta (7.5) | 0.95% | — | Perforce Helix Core | 8/11/2023 | 17/6/2026 | In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner. | |
| Modificada | Crítica (9.8) | 0.68% | — | Felixwelberg SIS Handball | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Felix Welberg SIS Handball allows SQL Injection.This issue affects SIS Handball: from n/a through 1.0.45. | |
| Modificada | Alta (7.5) | 0.60% | — | Ortussolutions Coldbox Elixir | 6/11/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure. Upgrading to version 3.1.7 is able to address this issue. The… | |
| Modificada | Alta (7.5) | 0.50% | — | Wallix Bastion | 23/10/2023 | 17/6/2026 | WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface. | |
| Modificada | Baja (3.7) | 0.41% | — | Plixer Scrutinizer | 12/10/2023 | 17/6/2026 | An issue was discovered in Plixer Scrutinizer before 19.3.1. It exposes debug logs to unauthenticated users at the /debug/ URL path. With knowledge of valid IP addresses and source types, an unauthenticated attacker can download debug logs containing application-related information. | |
| Modificada | Crítica (9.8) | 0.70% | — | Plixer Scrutinizer | 12/10/2023 | 17/6/2026 | An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database… | |
| Modificada | Media (5.3) | 0.49% | — | Plixer Scrutinizer | 12/10/2023 | 17/6/2026 | An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV does not require authentication and allows an unauthenticated user to export a report and access the results. | |
| Modificada | Alta (8.8) | 0.24% | — | Felixwelberg SIS Handball | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Felix Welberg SIS Handball plugin <= 1.0.45 versions. | |
| Modificada | Alta (7.8) | 0.23% | — | Trellix Endpoint Security | 4/10/2023 | 17/6/2026 | A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code. | |
| Modificada | Crítica (9.8) | 0.67% | — | Turaconsulting Signalix | 15/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tura Signalix allows SQL Injection. This issue affects Signalix: 7T_0228. | |
| Modificada | Alta (7.1) | 0.15% | — | Trellix Data Loss Prevention | 14/9/2023 | 17/6/2026 | A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to. | |
| Modificada | Alta (7.5) | 0.94% | — | Netflix Dispatch | 17/8/2023 | 17/6/2026 | Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin - Basic Authentication Provider` plugin encounters an error when attempting to decode a JWT token. Any Dispatch users who own their… | |
| Modificada | Crítica (9.8) | 2.0% | — | Apache Helix | 26/7/2023 | 17/6/2026 | An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code execution. The code can be run in Helix REST start… | |
| Modificada | Media (6.1) | 2.2% | — | Apache Felix Health Check Webconsole Plugin | 25/7/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin… | |
| Modificada | Alta (8.8) | 0.94% | — | Trellix Enterprise Security Manager | 3/7/2023 | 17/6/2026 | A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain… | |
| Modificada | Alta (7.8) | 0.24% | — | Trellix Move | 3/7/2023 | 17/6/2026 | An unquoted Windows search path vulnerability existed in the install the MOVE 4.10.x and earlier Windows install service (mvagtsce.exe). The misconfiguration allowed an unauthorized local user to insert arbitrary code into the unquoted service path to obtain privilege escalation and stop antimalware services. | |
| Modificada | Alta (7.8) | 0.47% | — | Trellix Enterprise Security Manager | 3/7/2023 | 17/6/2026 | An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of privilege escalation or to execute arbitrary commands. | |
| Modificada | Alta (8.1) | 0.57% | — | Trellix Agent | 7/6/2023 | 17/6/2026 | A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, resulting in the service becoming unavailable. | |
| Modificada | Alta (7.8) | 0.65% | — | Trellix Agent | 7/6/2023 | 17/6/2026 | A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder. The malicious file is executed by running the TA deployment feature located in the System Tree. | |
| Modificada | Alta (7.5) | 0.79% | — | Netflix Lemur | 19/4/2023 | 15/7/2026 | Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur. | |
| Modificada | Media (6.5) | 0.64% | — | Trellix Agent | 3/4/2023 | 17/6/2026 | A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable. | |
| Modificada | Alta (7.8) | 0.17% | — | Trellix Agent | 3/4/2023 | 17/6/2026 | A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions. | |
| Modificada | Media (6.7) | 0.37% | — | Mcafee Advanced Threat DefenseTrellix Intelligent Sandbox | 13/3/2023 | 17/6/2026 | A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The… | |
| Modificada | Media (6.1) | 0.68% | — | Mind-elixir Project Mind-elixir | 20/2/2023 | 17/6/2026 | Mind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting when handling untrusted menus. This issue is patched in version 0.18.1 |