Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
3971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.62% | — | Pega Platform | 7/8/2023 | 17/6/2026 | Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials | |
| Modificada | Media (5) | 1.3% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Linuxone+1 | 4/8/2023 | 17/6/2026 | Se ha encontrado un fallo en la autenticación de usuarios en OpenID Connect de Keycloak, que podría autenticar incorrectamente las solicitudes. Un atacante autenticado que pudiera obtener información de una solicitud de usuario dentro del mismo entorno, podría utilizar esos datos para hacerse pasar por la víctima y… | |
| Modificada | Alta (7.8) | 0.16% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+8 | 3/8/2023 | 17/6/2026 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform | 3/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Analizada | Media (4.3) | 0.58% | — | Liferay Digital Experience PlatformLiferay Portal | 2/8/2023 | 17/6/2026 | El selector de organizaciones en Liferay Portal v7.4.3.81 a v7.4.3.85 y Liferay DXP v7.4 actualización 81 a 85 no comprueba el permiso del usuario, lo que permite a usuarios remotos autenticados obtener una lista de todas las organizaciones. | |
| Modificada | Media (5.3) | 0.70% | — | IBM Tririga Application Platform | 31/7/2023 | 17/6/2026 | IBM TRIRIGA v3.0, v4.0 y v4.4 podrían permitir a un atacante remoto obtener información sensible cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría utilizarse en ataques posteriores contra el sistema. ID de IBM X-Force: 190744. | |
| Modificada | Media (4.3) | 0.75% | — | Solarwinds Platform | 26/7/2023 | 17/6/2026 | Vulnerabilidad de Access Control Bypass en SolarWinds Platform que permite a un usuario con privilegios leer recursos arbitrarios | |
| Modificada | Baja (3.5) | 0.77% | — | Solarwinds Platform | 26/7/2023 | 17/6/2026 | SolarWinds Platform era susceptible a la vulnerabilidad de neutralización de entrada incorrecta. Esta vulnerabilidad permite a un adversario remoto con una cuenta válida de SolarWinds Platform anexar parámetros de URL para inyectar HTML pasivo. | |
| Modificada | Alta (7.2) | 3.2% | — | Solarwinds Platform | 26/7/2023 | 17/6/2026 | La plataforma SolarWinds era susceptible a la vulnerabilidad de comparación incorrecta. Esta vulnerabilidad permite a los usuarios con acceso administrativo a SolarWinds Web Console ejecutar comandos arbitrarios con privilegios SYSTEM. | |
| Modificada | Alta (7.2) | 2.8% | — | Solarwinds Platform | 26/7/2023 | 17/6/2026 | The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges. | |
| Modificada | Alta (7.2) | 3.0% | — | Solarwinds Platform | 26/7/2023 | 17/6/2026 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges. | |
| Modificada | Alta (7.2) | 2.6% | — | Solarwinds Platform | 26/7/2023 | 17/6/2026 | The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands. | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Openstack Platform | 25/7/2023 | 17/6/2026 | An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests,… | |
| Modificada | Media (6.1) | 0.39% | — | Bugfinder Listplace Directory Listing Platform | 22/7/2023 | 17/6/2026 | A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0. It has been classified as problematic. This affects an unknown part of the file /listplace/user/coverPhotoUpdate of the component Photo Handler. The manipulation of the argument user_cover_photo leads to cross site scripting. It is… | |
| Modificada | Media (6.1) | 0.39% | — | Bugfinder Listplace Directory Listing Platform | 22/7/2023 | 17/6/2026 | A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /listplace/user/ticket/create of the component HTTP POST Request Handler. The manipulation of the argument message leads to cross site… | |
| Modificada | Crítica (9.8) | 0.45% | — | GSS Vitals Enterprise Social Platform | 21/7/2023 | 17/6/2026 | Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0. | |
| Modificada | Crítica (9.8) | 1.3% | — | Openidentityplatform Openam | 20/7/2023 | 17/6/2026 | Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process.… | |
| Modificada | Media (6.1) | 0.45% | — | Tduckcloud Tduck-platform | 19/7/2023 | 9/7/2026 | An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file. | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Crítica (9.8) | 1.1% | — | Orchid Platform | 11/7/2023 | 17/6/2026 | Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-alpha4 and prior to version 14.5.0 is related to the deserialization of untrusted data from the `_state` query parameter, which can result… | |
| Modificada | Alta (7.5) | 1.6% | — | QemuRedhat Openstack PlatformRedhat Enterprise LinuxFedoraproject Fedora | 11/7/2023 | 17/6/2026 | A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the… | |
| Modificada | Media (6.1) | 0.51% | — | Gzscripts GZ E Learning Platform | 10/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts GZ E Learning Platform 1.8 and classified as problematic. This issue affects some unknown processing of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-233357 was assigned to this… | |
| Modificada | Media (6.1) | 0.51% | — | Gzscripts PHP CRM Platform | 10/7/2023 | 17/6/2026 | A vulnerability has been found in GZ Scripts PHP CRM Platform 1.8 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is… | |
| Modificada | Media (6.1) | 0.69% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Linuxone+1 | 7/7/2023 | 17/6/2026 | Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri. | |
| Modificada | Alta (7.5) | 0.52% | — | Redhat Openshift Container PlatformRedhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR PowerRedhat Openshift Container Platform IBM Z Systems+1 | 5/7/2023 | 17/6/2026 | A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated. |