Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

3363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.37%—Connections-pro Connections Business Directory26/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin <= 10.4.36 versions.
ModificadaMedia (6.1)0.55%—Zscaler Client Connector22/6/202317/6/2026
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login.
ModificadaMedia (6.1)0.45%—Zscaler Client Connector22/6/202317/6/2026
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain.
ModificadaMedia (5.7)0.29%—SAP Digital ManufacturingSAP Plant Connectivity13/6/202317/6/2026
SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the internal network could send service requests…
ModificadaAlta (8.8)1.8%💥 PoCSnowflake Connector8/6/202317/6/2026
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(SSO) browser URL authentication. In order to exploit the potential for command…
ModificadaAlta (8.8)1.9%—Snowflake Connector8/6/202317/6/2026
snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and…
ModificadaAlta (8.8)1.4%—Snowflake Connector8/6/202317/6/2026
snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to…
ModificadaMedia (4.3)0.52%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect246/6/202317/6/2026
Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authorized remote attacker with low privileges to view a limited amount of another accounts contact information.
ModificadaAlta (8.8)0.79%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect246/6/202317/6/2026
An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to take over the admin user and therefore…
ModificadaAlta (7.8)0.24%—IBM Aspera CargoIBM Aspera Connect5/6/202317/6/2026
IBM Aspera Connect v4.2.5 e IBM Aspera Cargo v4.2.5 son vulnerables a un desbordamiento de búfer, causado por una comprobación de límites incorrecta. Un atacante podría desbordar un búfer y ejecutar código arbitrario en el sistema. IBM X-Force ID: 248625.
ModificadaAlta (7.5)0.55%—IBM Aspera CargoIBM Aspera Connect5/6/202317/6/2026
IBM Aspera Connect e IBM Aspera Cargo 4.2.5 transmite credenciales de autenticación, pero utiliza un método inseguro que es susceptible de ser interceptado y/o recuperado sin autorización. IBM X-Force ID: 244107
ModificadaMedia (6.5)0.34%—Dell Secure Connect Gateway1/6/202317/6/2026
Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.
ModificadaMedia (6.1)0.35%—Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector30/5/202317/6/2026
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
ModificadaMedia (5.3)0.57%—Netapp Blue XP Connector26/5/202317/6/2026
NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architecture resolves this issue - obtaining the fix requires redeploying a fresh Connector.
ModificadaBaja (3.7)2.2%—Haxx CurlFedoraproject FedoraApple MacosNetapp Clustered Data Ontap+526/5/202317/6/2026
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which…
ModificadaMedia (5.9)1.8%—Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+626/5/202317/6/2026
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private…
ModificadaMedia (5.9)2.7%—Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+426/5/202317/6/2026
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to use the synchronous resolver, it allows name resolves to time-out slow operations using `alarm()` and `siglongjmp()`. When doing this,…
ModificadaAlta (7.5)2.5%—Haxx CurlApple MacosNetapp Clustered Data OntapNetapp Ontap Antivirus Connector+426/5/202317/6/2026
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting…
ModificadaCrítica (9.8)0.92%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce a password change. A successful exploit…
AnalizadaAlta (7.4)0.62%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page. A successful exploit could allow an attacker to execute…
ModificadaAlta (7.2)1.7%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient restriction on URL parameters.
ModificadaAlta (8.8)0.39%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful…
ModificadaCrítica (9.8)0.99%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.
ModificadaMedia (6.1)0.41%—Mitel Mivoice Connect24/5/202317/6/2026
A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the home.php page. A successful exploit could allow…
ModificadaCrítica (9.8)1.2%—Garmin Connect-iq23/5/202317/6/2026
The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call its `add` method, override arbitrary…