Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

5122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.50%—Qudata Qubot19/6/202317/6/2026
The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflected on the user dashboard.
ModificadaAlta (7.5)0.76%—Cdatatec WEB Management System18/6/202317/6/2026
A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affects an unknown part of the file /cgi-bin/jumpto.php?class=user&page=config_save&isphp=1 of the component User Creation Handler. The manipulation of the argument user/newpassword leads to improper…
ModificadaAlta (7.5)4.0%💥 ExploitCdata ARC16/6/202317/6/2026
CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
ModificadaMedia (6.1)0.38%—Zestard Admin Side Data Storage FOR Contact Form 715/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <= 1.1.1 versions.
ModificadaMedia (4.7)0.35%—Fasterxml Jackson-databind14/6/202317/6/2026
jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that this is not a valid vulnerability report, because the steps of constructing a cyclic data structure and trying to…
ModificadaMedia (6.1)0.22%—SAP Master Data Synchronization13/6/202317/6/2026
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.
ModificadaCrítica (9.8)1.6%—Progress Datadirect Odbc Oracle Wire Protocol Driver9/6/202317/6/2026
A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allows an attacker to execute code of their choice on an affected host by copying…
ModificadaMedia (5.9)0.32%—Progress Datadirect Odbc Oracle Wire Protocol Driver9/6/202317/6/2026
An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, if an error is encountered initializing the encryption object used to encrypt data, the code falls back to a different encryption mechanism that uses an insecure random…
ModificadaMedia (5.3)0.59%—Trianglemicroworks Scada Data Gateway7/6/202317/6/2026
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker…
ModificadaCrítica (9.8)0.71%—Trianglemicroworks Scada Data Gateway7/6/202317/6/2026
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly…
ModificadaMedia (6.5)0.94%—Redhat Openshift API FOR Data ProtectionRedhat Openshift Container PlatformRedhat Openshift Developer Tools AND Services6/6/202317/6/2026
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array,…
ModificadaCrítica (9.8)1.3%—Dataease1/6/202317/6/2026
DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7. There are no known workarounds aside from upgrading.
ModificadaAlta (8.1)1.0%—Dataease1/6/202317/6/2026
DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or interfering with the interface for marking…
ModificadaAlta (8.8)0.81%—Saison Dataspider Servista1/6/202317/6/2026
DataSpider Servista versión 4.4 y anteriores utilizan una clave criptográfica embebida. DataSpider Servista es un software de integración de datos."ScriptRunner" y "ScriptRunner para Amazon SQS" se utilizan para iniciar los procesos configurados en DataSpider Servista. La clave criptográfica embebida se encuentra en…
ModificadaCrítica (9.8)1.3%—Fox-it FOX Datadiode Firmware31/5/202317/6/2026
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of this issue does not require user…
ModificadaAlta (7.5)0.84%—Fox-it FOX Datadiode Firmware31/5/202317/6/2026
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a Divide-by-Zero vulnerability in the packet parser. A remote attacker could leverage this vulnerability to cause a denial-of-service. Exploitation of this issue does not require user interaction.
ModificadaAlta (7.5)1.9%—OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+730/5/202317/6/2026
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
ModificadaBaja (3.7)2.2%—Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+526/5/202317/6/2026
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which…
ModificadaMedia (5.9)1.8%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+626/5/202317/6/2026
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private…
ModificadaMedia (5.9)2.7%—Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+426/5/202317/6/2026
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this,…
ModificadaAlta (7.5)2.5%—Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+426/5/202317/6/2026
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting…
ModificadaAlta (7.5)0.46%—Talend Data Catalog26/5/202317/6/2026
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)
ModificadaMedia (6.1)0.47%—Broadcom Vmware Nsx-t Data Center26/5/202317/6/2026
NSX-T contiene una vulnerabilidad de cross-site scripting reflejado debido a la falta de validación de entrada. Un atacante remoto puede inyectar HTML o JavaScript para redirigir a páginas maliciosas.
ModificadaAlta (8.8)0.26%—Sigmaplugin Advanced Database Cleaner23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions.
ModificadaAlta (8.1)0.51%—Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+1822/5/202317/6/2026
The iBoot device’s basic discovery protocol assists in initial device configuration. The discovery protocol shows basic information about devices on the network and allows users to perform configuration changes.