Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
5407 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.80% | — | Nextcloud Server | 23/6/2023 | 17/6/2026 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0… | |
| Modificada | Media (6.5) | 0.49% | — | Nextcloud End-to-end Encryption | 23/6/2023 | 17/6/2026 | Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4… | |
| Modificada | Crítica (9.1) | 0.92% | — | Nextcloud Server | 23/6/2023 | 17/6/2026 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0… | |
| Modificada | Media (6.1) | 0.59% | — | Nextcloud Server | 23/6/2023 | 17/6/2026 | NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. Starting in version 26.0.0 and prior to version 26.0.2, an attacker could supply a URL that redirects an unsuspecting victim from a legitimate domain to an attacker's site. Nextcloud Server and… | |
| Modificada | Alta (8.8) | 0.90% | — | Amazon AWS Cloud Development KIT | 23/6/2023 | 17/6/2026 | AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. In the packages `aws-cdk-lib` 2.0.0 until 2.80.0 and `@aws-cdk/aws-eks` 1.57.0 until 1.202.0, `eks.Cluster` and `eks.FargateCluster` constructs create… | |
| Modificada | Alta (7.6) | 0.22% | — | Nvidia GPU Display DriverNvidia Virtual GPUNvidia Cloud Gaming | 23/6/2023 | 17/6/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, which may lead to code execution, denial of service, escalation of privileges, data tampering, or information disclosure. | |
| Modificada | Alta (7.5) | 0.87% | — | Nextcloud Server | 22/6/2023 | 17/6/2026 | Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are sent in parallel, all of them were executed even if the amount of faulty requests succeeded the limit by the time the response was sent to the client. This allowed someone to send as many requests… | |
| Modificada | Media (6.1) | 0.38% | — | Tags Cloud Manager Project Tags Cloud Manager | 22/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aakif Kadiwala Tags Cloud Manager plugin <= 1.0.0 versions. | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Mgt-commerce Cloudpanel | 20/6/2023 | 17/6/2026 | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. | |
| Modificada | Alta (7.3) | 0.75% | — | Cloudflare Warp | 20/6/2023 | 17/6/2026 | Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient access control policy on an IPC Named Pipe. This would have enabled an attacker to trigger WARP connect and disconnect commands, as well as obtaining network diagnostics… | |
| Modificada | Media (4.8) | 0.44% | — | Quantumcloud Wpbot | 19/6/2023 | 17/6/2026 | The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot | |
| Modificada | Media (4.8) | 0.47% | — | Quantumcloud Wpbot | 19/6/2023 | 17/6/2026 | The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 17/6/2023 | 17/6/2026 | Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | |
| Modificada | Media (6.5) | 0.54% | — | Pivotal Cloud Foundry NFS VolumePivotal Cloud Foundry NotificationsPivotal Cloud Foundry SMB Volume | 16/6/2023 | 17/6/2026 | Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19. | |
| Modificada | Media (5.4) | 0.54% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/6/2023 | 17/6/2026 | Las versiones 6.5.16.0 (y anteriores) de Adobe Experience Manager se ven afectadas por una vulnerabilidad de Cross-Site Scripting (XSS) Reflejado. Si un atacante con pocos privilegios es capaz de convencer a una víctima para que visite una URL que haga referencia a una página vulnerable, se puede ejecutar contenido… | |
| Modificada | Media (5.4) | 0.51% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/6/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction. | |
| Modificada | Media (5.4) | 0.51% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/6/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | |
| Modificada | Media (5.4) | 0.51% | — | Adobe Experience ManagerAdobe Experience Manager Cloud Service | 15/6/2023 | 17/6/2026 | Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | |
| Modificada | Alta (7.5) | 0.71% | — | Cloudflare Lua-resty-json | 14/6/2023 | 17/6/2026 | A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have allowed an attacker to launch a DoS if the function was used to parse untrusted input data. It is important to note that because this debug… | |
| Modificada | Alta (7.5) | 2.2% | — | Cloudflare Cfnts | 14/6/2023 | 17/6/2026 | An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b https://github.com/cloudflare/cfnts/commit/783490b913f05e508a492cd7b02e3c4ec2297b71 enabled a remote attacker to trigger a panic by sending an NTSAuthenticator packet with extension length longer than the packet contents. | |
| Modificada | Alta (8.1) | 0.47% | — | Arista Cloudvision Portal | 13/6/2023 | 17/6/2026 | On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision… | |
| Modificada | Alta (7.5) | 0.59% | — | Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+8 | 12/6/2023 | 17/6/2026 | Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102;… | |
| Modificada | Alta (7.5) | 1.4% | — | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 6/6/2023 | 17/6/2026 | An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) v9.0 Initial Release to v13.0 Initial Release allows attackers to bypass authorization rules. | |
| Modificada | Alta (7.8) | 0.47% | 💥 PoC | Mgt-commerce Cloudpanel | 6/6/2023 | 17/6/2026 | CloudPanel v2.2.2 allows attackers to execute a path traversal. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Progress Moveit CloudProgress Moveit Transfer | 2/6/2023 | 17/6/2026 | En Progress MOVEit Transfer antes de 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5) y 2023.0.1 (15.0.1), se ha encontrado una vulnerabilidad de inyección SQL en la aplicación web MOVEit Transfer que podría permitir que un atacante no autenticado obtenga acceso a la base de datos de MOVEit… |