Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
474 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.73% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+10 | 15/5/2023 | 17/6/2026 | Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 15/5/2023 | 17/6/2026 | In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise. | |
| Modificada | Media (5.3) | 1.4% | — | Apache CouchdbIBM Cloudant | 2/5/2023 | 17/6/2026 | This doesn't affect map/reduce or search (Dreyfus) index functions. Users are recommended to upgrade to a version that is no longer affected by this issue (Apache CouchDB 3.3.2 or 3.2.3). Workaround: Avoid using design documents from untrusted sources which may attempt to cache or store data in the Javascript… | |
| Modificada | Crítica (9.8) | 1.3% | — | Shanling Eddict PlayerShanling Mtouch OS | 25/4/2023 | 17/6/2026 | A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via directory traversal. | |
| Analizada | Alta (8.8) | 41% | ⚠ Explotación activa💥 PoC | Google ChromeDebian LinuxFedoraproject FedoraCouchbase Server | 14/4/2023 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 0.88% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+12 | 23/3/2023 | 17/6/2026 | In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device. | |
| Modificada | Media (5.3) | 0.63% | — | Couchbase Server | 23/3/2023 | 17/6/2026 | In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. | |
| Modificada | Crítica (9.8) | 42% | 💥 Exploit | Codemenschen Gift Vouchers | 22/3/2023 | 17/6/2026 | The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action. | |
| Modificada | Media (5.5) | 0.19% | — | Samsung Bixbytouch | 16/3/2023 | 17/6/2026 | Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files. | |
| Modificada | Crítica (9.8) | 1.1% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. | |
| Modificada | Media (5.3) | 0.25% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the… | |
| Modificada | Crítica (9.8) | 0.74% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device. | |
| Modificada | Media (6.1) | 0.38% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability. | |
| Modificada | Media (4.2) | 0.27% | — | Onekey Touch FirmwareOnekey Mini Firmware | 14/2/2023 | 17/6/2026 | Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, "man-in-the-middle" does not refer to the attacker's position on an IP network). NOTE: the… | |
| Modificada | Media (5.9) | 0.95% | — | Bticino Door Entry FOR Hometouch | 6/2/2023 | 17/6/2026 | BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate. | |
| Modificada | Alta (7.5) | 0.45% | — | Couchbase Server | 6/2/2023 | 17/6/2026 | Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor. | |
| Modificada | Alta (8.1) | 0.66% | — | Couchbase Server | 6/2/2023 | 17/6/2026 | An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using… | |
| Modificada | Media (4.9) | 0.96% | — | Couchbase Server | 6/2/2023 | 17/6/2026 | An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase Server Backup Service can exhaust memory resources, causing the process to be killed, which can be used for denial of service. | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.31% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 1/2/2023 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.24% | — | HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+177 | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.24% | — | HP Elite Dragonfly FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 FirmwareHP Elite X2 G4 Firmware+177 | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Media (5.9) | 0.63% | — | Wago Pfc100 FirmwareWago Pfc200 FirmwareWago Touch Panel 600 Advanced FirmwareWago Touch Panel 600 Standard Firmware+3 | 19/1/2023 | 17/6/2026 | The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull. | |
| Modificada | Alta (8.8) | 0.92% | — | Bravenewcode Wptouch | 9/1/2023 | 17/6/2026 | The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentionally or not) a malicious settings file and a suitable gadget chain is present on the blog. |