Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3185▲ 600 respecto a la semana anterior
Críticas / altas1508▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
5407 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 1.3% | — | Oracle GraalvmOracle JDKOracle JRENetapp 7-mode Transition Tool+6 | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows… | |
| Modificada | Alta (7) | 0.17% | — | Qualys Cloud Agent | 18/4/2023 | 17/6/2026 | Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (macOS 10.15 and older) versions. Attackers may exploit incorrect file permissions to give them ROOT command execution privileges on the host.… | |
| Modificada | Alta (7) | 0.13% | — | Qualys Cloud Agent | 18/4/2023 | 17/6/2026 | A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges limited on the local machine during uninstallation of the Qualys Cloud Agent for Windows. Attackers may gain SYSTEM level privileges on that asset to run… | |
| Modificada | Media (6.3) | 0.18% | — | Qualys Cloud Agent | 18/4/2023 | 17/6/2026 | An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack vector. This allows attackers to assume the privileges of the process, and they may delete or otherwise on unauthorized files, allowing for… | |
| Modificada | Alta (7) | 0.22% | — | Qualys Cloud Agent | 18/4/2023 | 17/6/2026 | An Executable Hijacking condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers may load a malicious copy of a Dependency Link Library (DLL) via a local attack vector instead of the DLL that the application was expecting, when processes are running with escalated… | |
| Modificada | Media (4.3) | 0.66% | — | Nextcloud Talk | 17/4/2023 | 17/6/2026 | Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that… | |
| Modificada | Alta (8.8) | 0.63% | — | Nextcloud Files Automated TaggingNextcloud Server | 17/4/2023 | 17/6/2026 | Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to… | |
| Modificada | Media (4.9) | 0.42% | — | Tigergraph CloudTigergraph Enterprise | 14/4/2023 | 17/6/2026 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph… | |
| Modificada | Media (6.5) | 0.71% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation… | |
| Modificada | Alta (8.8) | 0.96% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /settings/guest-settings endpoint, the /settings/samlusers-settings endpoint, and the /settings/users-settings endpoint. A malicious user (already… | |
| Modificada | Media (6.5) | 0.72% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in the OnlyOffice backend of other users by guessing the file ID of a target file. | |
| Modificada | Crítica (9.8) | 1.0% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and can be bypassed by passing any string… | |
| Modificada | Crítica (9.8) | 1.0% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding… | |
| Modificada | Media (6.5) | 0.44% | — | Liveboxcloud Vdesk | 14/4/2023 | 17/6/2026 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user. | |
| Modificada | Alta (8.8) | 0.83% | — | Tigergraph CloudTigergraph Enterprise | 13/4/2023 | 17/6/2026 | An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be read from the configuration file. Using this token on the REST API provides an attacker with anonymous admin-level privileges on all REST API endpoints. | |
| Modificada | Alta (7.5) | 0.78% | — | Arista Cloudeos | 12/4/2023 | 17/6/2026 | On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding… | |
| Modificada | Alta (7.5) | 0.68% | — | Arista Cloudeos | 12/4/2023 | 17/6/2026 | On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding… | |
| Modificada | Alta (8.2) | 1.2% | — | Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+2 | 10/4/2023 | 17/6/2026 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,… | |
| Modificada | Alta (7.8) | 0.29% | — | Cloudflare Warp | 6/4/2023 | 17/6/2026 | Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious attacker to forge the destination of the hardlink and escalate privileges, overwriting SYSTEM protected files. As Cloudflare WARP client… | |
| Modificada | Media (4.8) | 0.39% | — | Quantumcloud Conversational Forms FOR Chatbot | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin <= 1.1.6 versions. | |
| Modificada | Alta (7.8) | 0.29% | — | Cloudflare Warp | 5/4/2023 | 17/6/2026 | An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to perform privileged operations with SYSTEM context by working with a combination of opportunistic locks (oplock) and symbolic links (which can both be created by an… | |
| Modificada | Media (6.5) | 0.39% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop client to encrypt files with a key known to… | |
| Modificada | Media (6.4) | 0.68% | — | Nextcloud DesktopNextcloud | 4/4/2023 | 17/6/2026 | Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder… | |
| Modificada | Media (6.1) | 0.68% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder structure, and add new files. Users should… | |
| Modificada | Media (6.5) | 1.1% | — | Nextcloud Desktop | 4/4/2023 | 17/6/2026 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users should upgrade the Nextcloud Desktop client to 3.6.5 to receive a patch.… |