Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 60 respecto a la semana anterior
Críticas / altas1269▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
3702 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.45% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field. | |
| Modificada | Media (4.9) | 0.77% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo,… | |
| Modificada | Crítica (9.8) | 1.5% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western… | |
| Modificada | Media (4.9) | 0.57% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My… | |
| Modificada | Alta (7.5) | 1.0% | — | Coala Git-url-parse | 15/5/2023 | 17/6/2026 | giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an… | |
| Modificada | Media (6.5) | 0.73% | — | Gitlab | 12/5/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI. | |
| Modificada | Alta (7.8) | 0.21% | — | Digitalpersona Fpsensor Project Digitalpersona Fpsensor | 11/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in DigitalPersona FPSensor 1.0.0.1. This issue affects some unknown processing of the file C:\Program Files (x86)\FPSensor\bin\DpHost.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-228773… | |
| Modificada | Media (5.5) | 0.14% | — | Westerndigital MY Cloud OS | 10/5/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud… | |
| Modificada | Crítica (9.8) | 1.4% | — | Westerndigital MY Cloud OS | 10/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution… | |
| Modificada | Crítica (9.8) | 1.8% | — | Westerndigital MY Cloud OS | 10/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119. | |
| Modificada | Alta (7.5) | 0.30% | — | Westerndigital MY Cloud Home FirmwareWesterndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI Firmware | 10/5/2023 | 17/6/2026 | An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. | |
| Modificada | Alta (8.1) | 0.56% | — | Westerndigital MY Cloud Home DUO FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home Firmware | 10/5/2023 | 17/6/2026 | A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to… | |
| Modificada | Media (4.8) | 0.37% | — | Blackandwhitedigital Treepress | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Black and White Digital Ltd TreePress – Easy Family Trees & Ancestor Profiles plugin <= 2.0.22 versions. | |
| Modificada | Media (4.3) | 0.46% | — | Westerndigital MY CloudWesterndigital MY Cloud HomeWesterndigital MY Cloud OS 5Westerndigital Sandisk IBI | 8/5/2023 | 17/6/2026 | A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing… | |
| Modificada | Media (6.5) | 5.0% | — | Gitlab | 8/5/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitLab user may use a GraphQL endpoint to attach a malicious runner… | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Ultimate Carousel FOR Elementor | 8/5/2023 | 17/6/2026 | The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Mega Addons FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.44% | — | Topdigitaltrends Ultimate Carousel FOR Wpbakery Page Builder | 8/5/2023 | 17/6/2026 | The Ultimate Carousel For WPBakery Page Builder WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Virtualreception Digital Reciptie | 4/5/2023 | 17/6/2026 | Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request. | |
| Modificada | Alta (8.8) | 1.0% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thus leading to… | |
| Modificada | Media (5.7) | 0.89% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a… | |
| Modificada | Alta (8.1) | 0.83% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from… | |
| Modificada | Alta (8) | 1.0% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone… | |
| Modificada | Media (4.3) | 0.76% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions, an attacker may be able to map a private email of a GitLab user to their GitLab account on an instance. | |
| Modificada | Media (4.3) | 0.81% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables. |