Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
8751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.6) | 0.29% | — | Cisco DUO | 28/6/2023 | 17/6/2026 | A vulnerability in Cisco Duo Two-Factor Authentication for macOS could allow an authenticated, physical attacker to bypass secondary authentication and access an affected macOS device. This vulnerability is due to the incorrect handling of responses from Cisco Duo when the application is configured to fail open. An… | |
| Modificada | Alta (7.7) | 0.66% | — | Cisco Telepresence Video Communication Server | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway… | |
| Modificada | Media (4.8) | 0.48% | — | Cisco Sf200-24 FirmwareCisco Sf200-24fp FirmwareCisco Sf200-24p FirmwareCisco Sf200-48 Firmware+57 | 28/6/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack… | |
| Modificada | Media (6.5) | 0.52% | — | Cisco Secure Workload | 28/6/2023 | 17/6/2026 | A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials. This vulnerability is due to improper role-based access… | |
| Modificada | Media (6.1) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Media (6.1) | 0.51% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This… | |
| Modificada | Media (5.7) | 0.60% | — | Cisco Unified Communications Manager | 28/6/2023 | 17/6/2026 | A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… | |
| Modificada | Alta (7.5) | 0.93% | — | Cisco Unified Communications Manager IM AND Presence Service | 28/6/2023 | 17/6/2026 | A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to cause a temporary service outage for all Cisco Unified CM IM&P users who are attempting to authenticate to the service,… | |
| Modificada | Media (6.5) | 0.91% | — | Cisco Telepresence Video Communication Server | 28/6/2023 | 17/6/2026 | A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This vulnerability is due to incorrect handling… | |
| Modificada | Media (5.4) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Alta (7.5) | 0.93% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 28/6/2023 | 11/8/2026 | A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly,… | |
| Modificada | Alta (7.8) | 5.4% | 💥 PoC | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 28/6/2023 | 8/10/2026 | A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN… | |
| Modificada | Crítica (9.8) | 24% | 💥 PoC | Adiscon Loganalyzer | 20/6/2023 | 17/6/2026 | Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 0.55% | — | Cmscommander CMS Commander | 20/6/2023 | 17/6/2026 | The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. This makes it possible for unauthenticated attackers to the plugin to change the '_cmsc_public_key' in… | |
| Modificada | Media (6.8) | 0.51% | — | VW Discover Media Infotainment System | 16/6/2023 | 17/6/2026 | A lack of exception handling in the Volkswagen Discover Media Infotainment System Software Version 0876 allows attackers to cause a Denial of Service (DoS) via supplying crafted media files when connecting a device to the vehicle's USB plug and play feature. | |
| Modificada | Media (5.3) | 0.40% | — | Discourse | 13/6/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to reveal the number of topics recently created (but not the actual content thereof) in categories… | |
| Modificada | Media (5.3) | 0.42% | — | Discourse | 13/6/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, multiple duplicate topics could be created if topic embedding is enabled. This issue is patched in version 3.0.4 of the `stable` branch and version… | |
| Modificada | Media (5.3) | 0.36% | — | Discourse | 13/6/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulnerability and hide subsequent comments from other users. This… | |
| Modificada | Media (5.3) | 0.32% | — | Discourse | 13/6/2023 | 17/6/2026 | Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, if a site has modified their general category permissions, they could be set back to the default. This issue is patched in version 3.0.4 of the `stable`… | |
| Modificada | Alta (7.5) | 0.34% | — | Atlascopco Power Focus 6000 Firmware | 12/6/2023 | 17/6/2026 | Atlas Copco Power Focus 6000 web server is not a secure connection by default, which could allow an attacker to gain sensitive information by monitoring network traffic between user and controller. | |
| Modificada | Alta (7.5) | 0.56% | — | Atlascopco Power Focus 6000 Firmware | 12/6/2023 | 17/6/2026 | Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session. | |
| Modificada | Alta (7.5) | 0.34% | — | Atlascopco Power Focus 6000 Firmware | 12/6/2023 | 17/6/2026 | Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller. | |
| Modificada | Media (4.3) | 0.60% | — | Palscode Woocommerce Multi Currency | 7/6/2023 | 17/6/2026 | El plugin WooCommerce Multi Currency para WordPress es vulnerable a una falta de autorización en versiones hasta la v2.1.17 inclusive. Esto hace posible que atacantes autenticados cambien el precio de un producto a un valor arbitrario. | |
| Modificada | Media (6.1) | 0.58% | — | Rightpress Woocommerce Dynamic Pricing AND Discounts | 7/6/2023 | 17/6/2026 | The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1. This is due to missing sanitization on the settings imported via the import() function. This makes it possible for unauthenticated attackers to import a settings file… | |
| Modificada | Alta (8.8) | 0.68% | — | Hoppscotch | 5/6/2023 | 17/6/2026 | hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Attackers with access to read system logs will be able to elevate privilege with full access to the database. Users are advised to upgrade.… |