Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

313 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.31%—Brainstormforce Ultimate Addons FOR Wpbakery Page Builder27/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions.
ModificadaMedia (4.8)0.40%—Stormconsultancy Oauth Twitter Feed FOR Developers1/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy (Storm Consultancy) oAuth Twitter Feed for Developers plugin <= 2.3.0 versions.
ModificadaAlta (7.5)0.62%—Stormshield Network Security28/8/202317/6/2026
ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.
ModificadaMedia (5.3)0.29%—Stormshield SSL VPN Client28/8/202317/6/2026
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.
ModificadaAlta (7.8)0.19%—Stormshield SSL VPN Client25/8/202317/6/2026
Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.
ModificadaMedia (4.8)0.47%—Stormshield Network Security25/8/202317/6/2026
An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin panel. It is possible to inject malicious…
ModificadaAlta (7.8)0.19%—Stormshield SSL VPN Client5/8/202317/6/2026
An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Client, can use the OpenVPN instance to execute malicious code as administrator on the local machine.
ModificadaMedia (4.3)0.46%—Brainstormforce Lightweight Sidebar Manager1/7/202317/6/2026
The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the metabox_save() function. This makes it possible for unauthenticated attackers to save metbox data via a forged request…
ModificadaMedia (4.3)0.46%—Brainstormforce Import / Export Customizer Settings1/7/202317/6/2026
The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the astra_admin_errors() function. This makes it possible for unauthenticated attackers to display an import status…
ModificadaMedia (4.3)0.39%—Stormshield Endpoint Security27/6/202317/6/2026
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.
ModificadaMedia (5.5)0.19%—Stormshield Endpoint Security27/6/202317/6/2026
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.
ModificadaMedia (4.3)0.42%—Brainstormforce Spectra7/6/202317/6/2026
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+ roles to update the plugin's settings.
ModificadaMedia (4.3)0.41%—Stormshield Endpoint Security31/5/202317/6/2026
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control that allows an authenticated user can update global parameters.
ModificadaMedia (5.5)0.15%—Stormshield Endpoint Security30/5/202317/6/2026
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated users can read sensitive information.
AnalizadaAlta (8.8)0.26%—Brainstormforce Schema26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions.
ModificadaAlta (8.8)0.26%—Brainstormforce Starter Templates23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.
ModificadaBaja (3.3)0.17%—Jetbrains Phpstorm4/4/202317/6/2026
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
ModificadaMedia (5.3)7.0%💥 PoCCisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security1/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…
ModificadaMedia (5.4)0.51%—Brainstormforce Spectra21/2/202317/6/2026
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.
ModificadaAlta (7.5)1.8%—OpensslStormshield Management Center8/2/202317/6/2026
A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest initialization will fail. There is a missing check…
ModificadaAlta (7.4)60%—OpensslStormshield Management CenterStormshield Network Security8/2/202317/6/2026
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by…
ModificadaAlta (7.5)1.8%—OpensslStormshield Management Center8/2/202317/6/2026
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does…
ModificadaAlta (7.5)4.5%—OpensslStormshield Management Center8/2/202317/6/2026
The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new…
ModificadaAlta (7.5)20%—OpensslStormshield Network Security8/2/202317/6/2026
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is…
Orbitaley — Vulnerabilidades