Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 572 respecto a la semana anterior
Críticas / altas1455▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
3363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Garmin Connect-iq | 23/5/2023 | 17/6/2026 | The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the execution of the device's firmware. | |
| Modificada | Crítica (9.1) | 0.61% | — | Garmin Connect-iq | 23/5/2023 | 17/6/2026 | The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module without the user's consent and disclose… | |
| Modificada | Crítica (9.8) | 0.80% | — | Garmin Connect-iq | 23/5/2023 | 17/6/2026 | The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the… | |
| Modificada | Crítica (9.8) | 1.3% | — | Garmin Connect-iq | 23/5/2023 | 17/6/2026 | The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's… | |
| Modificada | Crítica (9.8) | 1.1% | — | Garmin Connect-iq | 23/5/2023 | 17/6/2026 | The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string,… | |
| Modificada | Crítica (9.8) | 1.3% | — | Garmin Connect-iq | 23/5/2023 | 17/6/2026 | The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call the API method with specially crafted parameters and hijack the execution of the device's firmware. | |
| Modificada | Alta (7.5) | 0.81% | — | Garmin Connect-iq | 23/5/2023 | 17/6/2026 | The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ modules, call their functions and disclose sensitive data such as user profile… | |
| Modificada | Crítica (9.8) | 1.5% | — | Garmin Connect-iq | 23/5/2023 | 17/6/2026 | The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with specially crafted parameters and hijack the… | |
| Modificada | Crítica (9.8) | 1.6% | — | Vibethemes BP Social Connect | 19/5/2023 | 17/6/2026 | The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Modificada | Media (4.3) | 0.58% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data… | |
| Modificada | Media (6.5) | 0.65% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | |
| Modificada | Media (6.5) | 0.65% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | |
| Modificada | Media (6.5) | 0.65% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files. | |
| Modificada | Alta (8.8) | 1.1% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.1% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 1.0% | — | Arubanetworks Edgeconnect Enterprise | 16/5/2023 | 17/6/2026 | Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system… | |
| Modificada | Alta (8.8) | 0.51% | — | IBM API Connect | 12/5/2023 | 17/6/2026 | IBM API Connect V10 could allow an authenticated user to perform actions that they should not have access to. IBM X-Force ID: 250585. | |
| Modificada | Media (5.5) | 0.17% | — | Intel Connect M | 10/5/2023 | 17/6/2026 | Uncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.16% | — | Intel Connect M | 10/5/2023 | 17/6/2026 | Improper access control in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.1) | 0.17% | — | F5 Nginx API Connectivity ManagerF5 Nginx Instance ManagerF5 Nginx Security Monitoring | 3/5/2023 | 17/6/2026 | NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.1) | 0.53% | — | Netapp Cloud BackupNetapp Ontap Select DeployF5 Nginx API Connectivity ManagerF5 Nginx Instance Manager+1 | 3/5/2023 | 17/6/2026 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.7) | 0.52% | — | Nvidia Connectx Firmware | 22/4/2023 | 17/6/2026 | NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service. |