Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

5407 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.46%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK17/7/202317/6/2026
IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380.
ModificadaBaja (3.7)0.50%—Jenkins Cloud Infrastructure Compute12/7/202317/6/2026
Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OCI clouds, enabling man-in-the-middle attacks.
ModificadaMedia (4.3)0.39%—Quantumcloud Slider Hero12/7/202317/6/2026
The Slider Hero plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.2.0. This is due to missing or incorrect nonce validation on the qc_slider_hero_duplicate() function. This makes it possible for unauthenticated attackers to duplicate slides via a forged request…
ModificadaAlta (8)6.4%—Kodcloud Kodbox10/7/202317/6/2026
Se ha encontrado una vulnerabilidad en kodbox v1.26. Ha sido declarada como crítica. Esta vulnerabilidad afecta a la función "Execute" del fichero "webconsole.php.txt" del componente "WebConsole Plug-In". La manipulación conduce a la inyección de comandos de tipo "os". El exploit ha sido revelado al público y puede…
ModificadaMedia (4.8)0.61%—Quantumcloud Wpbot10/7/202317/6/2026
The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)0.73%—Kodcloud Kodexplorer10/7/202317/6/2026
KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.
ModificadaAlta (8.8)0.31%—Configurable TAG Cloud Project Configurable TAG Cloud10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Keith Solomon Configurable Tag Cloud (CTC) plugin <= 5.2 versions.
ModificadaAlta (7.8)0.50%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data10/7/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 251782.
ModificadaMedia (6.5)0.98%—IBM Watson Knowledge Catalog ON Cloud PAK FOR Data10/7/202317/6/2026
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.
ModificadaMedia (4.3)0.72%—Cognos Analytics Cartridge FOR IBM Cloud PAK FOR Data10/7/202317/6/2026
IBM Cognos Analytics on Cloud Pak for Data 4.0 could allow an attacker to make system calls that might compromise the security of the containers due to misconfigured security context. IBM X-Force ID: 251465.
ModificadaAlta (7.5)1.3%—IBM Cloud PAK FOR DataIBM Watson Cp4d Data Stores10/7/202317/6/2026
IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with information specific to the system to cause a denial of service. IBM X-Force ID: 248924.
ModificadaAlta (8.8)0.49%—Tagdiv Cloud Library10/7/202317/6/2026
The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the…
ModificadaMedia (5.4)0.36%—IBM Cloud Object Storage System7/7/202317/6/2026
IBM Cloud Object System 3.15.8.97 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213650.
ModificadaAlta (8.8)2.3%—Fit2cloud 1panel5/7/202317/6/2026
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. The vulnerability has been fixed in v1.3.6.
ModificadaAlta (8.8)2.3%—Fit2cloud 1panel5/7/202317/6/2026
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerability has been fixed in v1.3.6.
ModificadaCrítica (9.8)0.69%—Westerndigital MY Cloud OS1/7/202317/6/2026
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.
ModificadaAlta (8.8)0.87%—Westerndigital MY Cloud OS30/6/202317/6/2026
A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300.
ModificadaMedia (6.7)1.3%—Westerndigital MY Cloud OS30/6/202317/6/2026
Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on vulnerable CGI files. This vulnerability can only be exploited over the network and the attacker must already have admin/root privileges to…
ModificadaCrítica (9.8)0.75%—Property Cloud Platform Management Center Project Property Cloud Platform Management Center29/6/202317/6/2026
Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
ModificadaAlta (7.5)0.61%—IBM Cloud PAK FOR Security27/6/202317/6/2026
IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another tenant's account. IBM X-Force ID: 254136.
ModificadaCrítica (9.8)0.46%—Fit2cloud Cloudexplorer Lite27/6/202317/6/2026
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of cloudexplorer-lite prior to 1.2.0 did not enforce strong passwords. This…
ModificadaMedia (6.1)0.48%—IBM Cloud PAK FOR Business Automation27/6/202317/6/2026
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 255587.
ModificadaAlta (8.8)0.78%—Fit2cloud Cloudexplorer Lite27/6/202317/6/2026
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.
ModificadaAlta (8.8)0.87%—Mgt-commerce Cloudpanel25/6/202317/6/2026
In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
ModificadaAlta (8.8)0.98%—Nextcloud Server23/6/202317/6/2026
Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 19.0.0 until 19.0.13.9, 20.0.0 until 20.0.14.14, 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0…