Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 568 respecto a la semana anterior
Críticas / altas1455▲ 53 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
5407 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.66% | — | Inpiazza Cloud Wifi | 1/6/2023 | 17/6/2026 | The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials. | |
| Modificada | Media (4.3) | 0.36% | — | SplunkSplunk Cloud Platform | 1/6/2023 | 17/6/2026 | On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, an unauthorized user can access the {{/services/indexing/preview}} REST endpoint to overwrite search results if they know the search ID (SID) of an existing search job. | |
| Modificada | Media (6.5) | 0.62% | — | SplunkSplunk Cloud Platform | 1/6/2023 | 17/6/2026 | In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulnerability in the {{dump}} SPL command to cause a denial of service by crashing the Splunk daemon. | |
| Modificada | Media (5.3) | 0.44% | — | SplunkSplunk Cloud Platform | 1/6/2023 | 17/6/2026 | In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can perform an unauthorized transfer of data from a search using the ‘copyresults’ command if they know the search ID (SID) of a search job that has recently run. | |
| Modificada | Media (4.3) | 0.39% | — | SplunkSplunk Cloud Platform | 1/6/2023 | 17/6/2026 | In Splunk Enterprise versions below 9.0.5, 8.2.11. and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user who holds the ‘user’ role can see the hashed version of the initial user name and password for the Splunk instance by using the ‘rest’ SPL command against the ‘conf-user-seed’… | |
| Modificada | Alta (8.8) | 0.75% | — | SplunkSplunk Cloud Platform | 1/6/2023 | 17/6/2026 | In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily. | |
| Modificada | Alta (8.8) | 79% | 💥 Exploit | SplunkSplunk Cloud Platform | 1/6/2023 | 17/6/2026 | En las versiones de Splunk Enterprise anteriores a 9.0.5, 8.2.11 y 8.1.14, y de Splunk Cloud Platform anteriores a la versión 9.0.2303.100, un usuario con pocos privilegios que tenga un rol que tenga asignada la capacidad de "edit_user" puede escalar sus privilegios a los del usuario administrador proporcionando… | |
| Modificada | Media (6.5) | 0.60% | — | SplunkSplunk Cloud Platform | 1/6/2023 | 17/6/2026 | On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon. | |
| Modificada | Media (6.1) | 0.35% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector | 30/5/2023 | 17/6/2026 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | |
| Modificada | Media (4.3) | 0.44% | — | Nextcloud Calendar | 30/5/2023 | 17/6/2026 | Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3 | |
| Modificada | Media (4.3) | 0.85% | — | Nextcloud Contacts | 30/5/2023 | 17/6/2026 | Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to be exploitable. It is recommended that… | |
| Modificada | Media (5.3) | 0.53% | — | Nextcloud Mail | 27/5/2023 | 17/6/2026 | Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3. | |
| Modificada | Media (6.5) | 0.70% | — | Nextcloud Server | 26/5/2023 | 17/6/2026 | Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints via the basic auth header allowed to brute-force user credentials when the provided user name was not an email address. Users from version 24.0.0 onward are affected. This issue has been addressed… | |
| Modificada | Media (4.3) | 0.38% | — | Fit2cloud Cloudexplorer | 26/5/2023 | 17/6/2026 | CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organization in CloudExplorer Lite. This is due to a missing permission check on the user profile. It is recommended to upgrade the version to v1.1.0. There are no known workarounds for this vulnerability. | |
| Modificada | Media (4.3) | 0.38% | — | Fit2cloud Cloudexplorer | 26/5/2023 | 17/6/2026 | CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organization/workspace permissions are not properly checked. This allows users to add themselves to any organization. This vulnerability has been fixed in v1.1.0. Users are advised to upgrade. There are… | |
| Modificada | Alta (8.8) | 3.3% | — | Nextcloud Cookbook | 26/5/2023 | 17/6/2026 | NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull-checks.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The `github.head_ref` value is an… | |
| Modificada | Media (6.7) | 0.21% | — | Nextcloud Server | 26/5/2023 | 17/6/2026 | Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other account the previous session would be… | |
| Modificada | Media (5.9) | 0.58% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing Release | 26/5/2023 | 17/6/2026 | In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and… | |
| Modificada | Crítica (9.8) | 0.85% | — | Nextcloud User Oidc | 25/5/2023 | 17/6/2026 | user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2 | |
| Modificada | Media (5.4) | 7.3% | 💥 Exploit | Cloudogu SCM Manager | 24/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field. | |
| Modificada | Media (5.4) | 0.74% | — | Fit2cloud Lina | 24/5/2023 | 17/6/2026 | Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission. | |
| Modificada | Alta (8.1) | 0.66% | — | Fit2cloud Cloudexplorer Lite | 23/5/2023 | 17/6/2026 | Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | |
| Modificada | Media (4.9) | 0.68% | — | Fit2cloud Cloudexplorer Lite | 23/5/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | |
| Modificada | Alta (8.1) | 0.36% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Loggregator-agent | 19/5/2023 | 17/6/2026 | Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the… | |
| Modificada | Media (4.9) | 0.77% | — | Westerndigital MY Cloud OS 5Westerndigital MY Cloud Home FirmwareWesterndigital Sandisk IBI FirmwareWesterndigital MY Cloud Home DUO Firmware | 18/5/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo,… |