Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3089▲ 499 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

5122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.1%—Atlassian Bamboo Data CenterAtlassian Bamboo Server19/7/202317/6/2026
This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center. This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call…
ModificadaAlta (8.8)2.2%—Atlassian Confluence Data CenterAtlassian Confluence Server18/7/202317/6/2026
Esta vulnerabilidad RCE (ejecución remota de código) de alta gravedad conocida como CVE-2023-22508 se introdujo en la versión 6.1.0 de Confluence Data Center & Server. Esta vulnerabilidad RCE (ejecución remota de código), con una puntuación CVSS de 8.5, permite a un atacante autenticado ejecutar código arbitrario…
ModificadaAlta (8.8)2.1%—Atlassian Confluence Data CenterAtlassian Confluence Server18/7/202317/6/2026
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to…
ModificadaBaja (3.1)0.41%—Oracle Database Server18/7/202317/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM.…
ModificadaMedia (4.9)0.50%—Oracle Database Server18/7/202317/6/2026
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this…
ModificadaBaja (3.7)0.39%—Oracle Database Server18/7/202317/6/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks of…
ModificadaMedia (6.1)0.50%—Solarwinds Database Performance Analyzer18/7/202317/6/2026
XSS attack was possible in DPA 2023.2 due to insufficient input validation
ModificadaAlta (7.5)2.0%—ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+217/7/202317/6/2026
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
ModificadaMedia (6.5)0.83%—Jenkins Datadog12/7/202317/6/2026
A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaMedia (6)0.20%—Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+1212/7/202317/6/2026
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected…
ModificadaAlta (7.2)0.86%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
ModificadaAlta (7.2)0.86%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.
ModificadaAlta (8.8)0.60%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration…
ModificadaAlta (8.8)0.60%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of…
ModificadaAlta (8.8)0.26%—Database Collation FIX Project Database Collation FIX11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dave Jesch Database Collation Fix plugin <= 1.2.7 versions.
ModificadaAlta (7.8)0.50%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data10/7/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
ModificadaMedia (6.5)0.98%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data10/7/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.
ModificadaMedia (4.3)0.72%—Cognos Analytics Cartridge FOR IBM Cloud PAK FOR Data10/7/202317/6/2026
IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465.
ModificadaAlta (7.5)1.3%—IBM Cloud PAK FOR DataIBM Watson Cp4d Data Stores10/7/202317/6/2026
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.
ModificadaAlta (8.8)1.2%—Amazon Aws-dataall28/6/202317/6/2026
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a data pipeline. The issue can only be triggered…
ModificadaMedia (6.5)0.45%—Dataease26/6/202317/6/2026
DataEase es una herramienta de análisis de visualización de datos de código abierto para analizar datos y obtener información sobre las tendencias empresariales. En las versiones afectadas, la falta de una comprobación de autorización permite a usuarios no autorizados manipular un cuadro de mando creado por el…
ModificadaMedia (6.5)0.71%—Dataease26/6/202317/6/2026
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed information includes md5 hashes of passwords, username, email, and…
ModificadaAlta (8.1)0.75%—Dataease26/6/202317/6/2026
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this…
ModificadaAlta (7.5)0.93%—Talend Data Catalog26/6/202317/6/2026
Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.
ModificadaMedia (4.8)0.44%—Qudata Qubot19/6/202317/6/2026
The QuBot WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).