Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
313 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.31% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 27/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Stormconsultancy Oauth Twitter Feed FOR Developers | 1/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for Developers plugin <= 2.3.0 versions. | |
| Modificada | Alta (7.5) | 0.62% | — | Stormshield Network Security | 28/8/2023 | 17/6/2026 | ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet. | |
| Modificada | Media (5.3) | 0.29% | — | Stormshield SSL VPN Client | 28/8/2023 | 17/6/2026 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book. | |
| Modificada | Alta (7.8) | 0.19% | — | Stormshield SSL VPN Client | 25/8/2023 | 17/6/2026 | Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions. | |
| Modificada | Media (4.8) | 0.47% | — | Stormshield Network Security | 25/8/2023 | 17/6/2026 | An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin panel. It is possible to inject malicious… | |
| Modificada | Alta (7.8) | 0.19% | — | Stormshield SSL VPN Client | 5/8/2023 | 17/6/2026 | An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine. | |
| Modificada | Media (4.3) | 0.46% | — | Brainstormforce Lightweight Sidebar Manager | 1/7/2023 | 17/6/2026 | The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the metabox_save() function. This makes it possible for unauthenticated attackers to save metbox data via a forged request… | |
| Modificada | Media (4.3) | 0.46% | — | Brainstormforce Import / Export Customizer Settings | 1/7/2023 | 17/6/2026 | The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the astra_admin_errors() function. This makes it possible for unauthenticated attackers to display an import status… | |
| Modificada | Media (4.3) | 0.39% | — | Stormshield Endpoint Security | 27/6/2023 | 17/6/2026 | Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators. | |
| Modificada | Media (5.5) | 0.19% | — | Stormshield Endpoint Security | 27/6/2023 | 17/6/2026 | Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges. | |
| Modificada | Media (4.3) | 0.42% | — | Brainstormforce Spectra | 7/6/2023 | 17/6/2026 | The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings. | |
| Modificada | Media (4.3) | 0.41% | — | Stormshield Endpoint Security | 31/5/2023 | 17/6/2026 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters. | |
| Modificada | Media (5.5) | 0.15% | — | Stormshield Endpoint Security | 30/5/2023 | 17/6/2026 | Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information. | |
| Analizada | Alta (8.8) | 0.26% | — | Brainstormforce Schema | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Brainstormforce Starter Templates | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions. | |
| Modificada | Baja (3.3) | 0.17% | — | Jetbrains Phpstorm | 4/4/2023 | 17/6/2026 | In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file | |
| Modificada | Media (5.3) | 7.0% | 💥 PoC | Cisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.… | |
| Modificada | Crítica (9.8) | 29% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+1 | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability… | |
| Modificada | Media (5.4) | 0.51% | — | Brainstormforce Spectra | 21/2/2023 | 17/6/2026 | The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks. | |
| Modificada | Alta (7.5) | 1.8% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check… | |
| Modificada | Alta (7.4) | 60% | — | OpensslStormshield Management CenterStormshield Network Security | 8/2/2023 | 17/6/2026 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by… | |
| Modificada | Alta (7.5) | 1.8% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does… | |
| Modificada | Alta (7.5) | 4.5% | — | OpensslStormshield Management Center | 8/2/2023 | 17/6/2026 | The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new… | |
| Modificada | Alta (7.5) | 20% | — | OpensslStormshield Network Security | 8/2/2023 | 17/6/2026 | The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is… |