Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
3971 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+184 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while fetching TX status information. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar9380 FirmwareQualcomm C-v2x 9150 Firmware+195 | 4/7/2023 | 17/6/2026 | Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+159 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+187 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while parsing QMI response message from firmware. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+201 | 4/7/2023 | 17/6/2026 | Memory Corruption in Audio while allocating the ion buffer during the music playback. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+267 | 4/7/2023 | 17/6/2026 | Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+197 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+93 | 4/7/2023 | 17/6/2026 | Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. | |
| Modificada | Crítica (9.8) | 0.36% | — | Qualcomm 315 5G FirmwareQualcomm 9205 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+156 | 4/7/2023 | 17/6/2026 | Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. | |
| Modificada | Media (6.8) | 0.19% | — | Qualcomm 315 5G FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 Firmware+208 | 4/7/2023 | 17/6/2026 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | |
| Modificada | Crítica (9.8) | 0.75% | — | Property Cloud Platform Management Center Project Property Cloud Platform Management Center | 29/6/2023 | 17/6/2026 | Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection. | |
| Modificada | Media (4.8) | 0.41% | — | Secnet Annet AC Centralized Management Platform | 29/6/2023 | 17/6/2026 | Annet AC Centralized Management Platform 1.02.040 is vulnerable to Stored Cross-Site Scripting (XSS) . | |
| Modificada | Crítica (9.8) | 3.2% | — | Parseplatform Parse-server | 28/6/2023 | 17/6/2026 | Parse Server es un backend de código abierto que puede desplegarse en cualquier infraestructura que pueda ejecutar Node.js. Antes de las versiones 5.5.2 y 6.2.1, un atacante puede utilizar un prototipo de "pollution sink" para desencadenar una ejecución remota de código a través del analizador BSON de MongoDB. Hay un… | |
| Modificada | Media (5.4) | 0.49% | — | Ibexa Ezpublish LegacyIbexa Ezpublish Platform | 26/6/2023 | 17/6/2026 | Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attacker to execute arbitrary code via the video-js.swf. | |
| Modificada | Crítica (9.8) | 0.53% | — | Pega Platform | 22/6/2023 | 17/6/2026 | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 17/6/2023 | 17/6/2026 | Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | |
| Analizada | Media (6.1) | 0.45% | — | Liferay Digital Experience PlatformLiferay Portal | 15/6/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter. | |
| Modificada | Media (4.8) | 0.39% | — | AC Centralized Management Platform Project AC Centralized Management Platform | 12/6/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in Youxun Electronic Equipment (Shanghai) Co., Ltd AC Centralized Management Platform v1.02.040 allows attackers to execute arbitrary code via uploading a crafted HTML file to the interface /upfile.cgi. | |
| Modificada | Media (6.1) | 0.44% | — | Pega Platform | 9/6/2023 | 17/6/2026 | Las versiones 7.2 a 8.8.1 de Pega Platform están afectadas por un problema de Cross-Site Scripting (XSS). | |
| Modificada | Baja (3.1) | 0.63% | — | IBM Txseries FOR MultiplatformIBM Cics TX | 8/6/2023 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to.… | |
| Modificada | Media (5.4) | 0.51% | — | IBM Txseries FOR MultiplatformIBM Cics TX | 8/6/2023 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Modificada | Baja (3.7) | 0.38% | — | IBM Cics TXIBM Txseries FOR Multiplatforms | 7/6/2023 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105. | |
| Modificada | Media (6.5) | 0.80% | — | IBM Cics TXIBM Txseries FOR Multiplatforms | 7/6/2023 | 17/6/2026 | IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly sensitive information by enabling debug mode. IBM X-Force ID: 257104. | |
| Modificada | Media (6.5) | 0.94% | — | Redhat Openshift API FOR Data ProtectionRedhat Openshift Container PlatformRedhat Openshift Developer Tools AND Services | 6/6/2023 | 17/6/2026 | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array,… | |
| Modificada | Alta (8.8) | 2.1% | — | Sitecore Experience Platform | 6/6/2023 | 17/6/2026 | Sitecore Experience Platform (XP) v9.3 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /Applications/Content%20Manager/Execute.aspx?cmd=convert&mode=HTML. |