Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.84% | — | Cisco Identity Services Engine | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these… | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Business 250-16p-2g FirmwareCisco Business 250-16t-2g FirmwareCisco Business 250-24fp-4g FirmwareCisco Business 250-24fp-4x Firmware+225 | 18/5/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper… | |
| Modificada | Alta (8.8) | 0.34% | — | Cisco Business 140ac Access Point FirmwareCisco Business 141acm FirmwareCisco Business 142acm FirmwareCisco Business 143acm Firmware+4 | 18/5/2023 | 17/6/2026 | A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login implementation. An attacker could exploit… | |
| Modificada | Alta (7.5) | 0.65% | — | Lightbend Akka ActorLightbend Akka Discovery | 11/5/2023 | 17/6/2026 | In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records, making DNS resolution subject to poisoning by an attacker. If the application performing discovery does not validate (e.g., via… | |
| Modificada | Alta (7.3) | 0.18% | — | Intel Pathfinder FOR Risc-v | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6) | 0.51% | — | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vmanage | 9/5/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands. An attacker with administrative privileges could exploit this… | |
| Modificada | Alta (8.8) | 0.86% | — | Cisco Staros | 9/5/2023 | 17/6/2026 | A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Crítica (9.8) | 37% | 💥 PoC | Cisco Spa112 Firmware | 4/5/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 1.8% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v2.x are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. | |
| Modificada | Crítica (9.8) | 0.92% | — | Illumina Iscan FirmwareIllumina Iseq 100 FirmwareIllumina Miniseq FirmwareIllumina Miseq Firmware+7 | 28/4/2023 | 17/6/2026 | Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor could upload and execute code remotely at the operating system level, which could allow an attacker to change settings, configurations, software, or access sensitive data… | |
| Modificada | Media (4.8) | 0.37% | — | Miniorange Wordpress Social Login AND Register (discord, Google, Twitter, Linkedin) | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions. | |
| Modificada | Media (5.3) | 0.43% | — | Discourse Reactions | 19/4/2023 | 17/6/2026 | Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable… | |
| Modificada | Media (4.9) | 0.39% | — | Discourse | 18/4/2023 | 17/6/2026 | Discourse is an open source platform for community discussion. In affected versions a user logged as an administrator can call arbitrary methods on the `SiteSetting` class, notably `#clear_cache!` and `#notify_changed!`, which when done on a multisite instance, can affect the entire cluster resulting in a denial of… | |
| Modificada | Media (5.4) | 0.36% | — | Discourse | 18/4/2023 | 17/6/2026 | Discourse is an open source platform for community discussion. Due to the improper sanitization of SVG files, an attacker can execute arbitrary JavaScript on the users’ browsers by uploading a crafted SVG file. This issue is patched in the latest stable and tests-passed versions of Discourse. Users are advised to… | |
| Modificada | Media (6.1) | 0.31% | — | Discourse | 18/4/2023 | 17/6/2026 | Discourse is an open source platform for community discussion. This vulnerability is not exploitable on the default install of Discourse. A custom feature must be enabled for it to work at all, and the attacker’s payload must pass the CSP to be executed. However, if an attacker succeeds in embedding Javascript that… | |
| Modificada | Baja (2.7) | 0.69% | — | Discourse | 18/4/2023 | 17/6/2026 | Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a Discourse administrator can lead to a long-running request and eventual timeout. This has the greatest potential impact in shared hosting environments where admins are untrusted. This issue has been… | |
| Modificada | Alta (7.8) | 0.16% | — | Openrisc Mor1kx Firmware | 18/4/2023 | 17/6/2026 | An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to the Exception Program Counter Register (EPCR) are not implemented correctly. User programs from an unauthorized privilege level can make read/write accesses to EPCR. | |
| Modificada | Media (4.3) | 0.41% | — | Openrisc Mor1kx Firmware | 18/4/2023 | 17/6/2026 | An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The write logic of Exception Effective Address Register (EEAR) is not implemented correctly. User programs from authorized privilege levels will be unable to write to EEAR. | |
| Modificada | Alta (8.8) | 1.1% | — | Openrisc Mor1kx Firmware | 18/4/2023 | 17/6/2026 | An issue was discovered in the ALU unit of the OpenRISC mor1kx processor. The carry flag is not being updated correctly for the subtract instruction, which results in an incorrect value of the carry flag. Any software that relies on this flag may experience corruption in execution. | |
| Modificada | Crítica (9.8) | 0.73% | — | Openrisc Or1200 Firmware | 18/4/2023 | 17/6/2026 | An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. Any software that relies on this flag may experience corruption in… | |
| Modificada | Crítica (9.8) | 0.73% | — | Openrisc Or1200 Firmware | 18/4/2023 | 17/6/2026 | An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated for the msb and mac instructions, which results in an incorrect value in the overflow flag. Any software that relies on this flag may experience corruption in… | |
| Analizada | Alta (7.2) | 54% | ⚠ Explotación activa | Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+2 | 13/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Identity Services Engine | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator… | |
| Modificada | Media (6.1) | 0.43% | — | Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+2 | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input… | |
| Modificada | Media (6.1) | 0.43% | — | Cisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+2 | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input… |