Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
4540 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.46% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 17/7/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380. | |
| Analizada | Media (4.3) | 0.44% | — | Agpt Autogpt Classic | 13/7/2023 | 17/6/2026 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GPT command line UI makes heavy use of color-coded print statements to signify different types of system messages to the user, including messages that are crucial for the user to review and control… | |
| Analizada | Alta (7.8) | 0.35% | — | Agpt Autogpt Classic | 13/7/2023 | 17/6/2026 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-GPT is executed directly on the host system via the provided run.sh or run.bat files, custom Python code execution is sandboxed using a temporary dedicated docker container which should not have… | |
| Analizada | Alta (8.8) | 0.36% | 💥 PoC | Agpt Autogpt Classic | 13/7/2023 | 17/6/2026 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Auto-GPT version prior to 0.4.3 by cloning the git repo and executing `docker compose run auto-gpt` in the repo root uses a different docker-compose.yml file from the one suggested in the official… | |
| Modificada | Alta (7.5) | 3.7% | — | Rockwellautomation 1756-en4tr FirmwareRockwellautomation 1756-en4trk FirmwareRockwellautomation 1756-en4trxt Firmware | 12/7/2023 | 17/6/2026 | Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages. | |
| Modificada | Crítica (9.8) | 5.5% | — | Rockwellautomation 1756-en2f Series A FirmwareRockwellautomation 1756-en2f Series B FirmwareRockwellautomation 1756-en2f Series C FirmwareRockwellautomation 1756-en2t Series A Firmware+8 | 12/7/2023 | 17/6/2026 | Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and… | |
| Modificada | Crítica (9.6) | 0.66% | — | Rockwellautomation Enhanced HIM | 11/7/2023 | 17/6/2026 | The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross-Origin Resource Sharing (CORS) settings and, as a result, is vulnerable to a Cross Site Request Forgery (CSRF) attack. To exploit this vulnerability, a malicious user… | |
| Modificada | Alta (8.8) | 0.93% | — | Rockwellautomation Powermonitor 1000 Firmware | 11/7/2023 | 17/6/2026 | The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote… | |
| Modificada | Media (6.5) | 0.22% | — | Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions. | |
| Modificada | Alta (7.5) | 0.81% | — | Dronecode PX4 Drone Autopilot | 6/7/2023 | 17/6/2026 | Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+184 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while fetching TX status information. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar9380 FirmwareQualcomm C-v2x 9150 Firmware+195 | 4/7/2023 | 17/6/2026 | Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+159 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+187 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while parsing QMI response message from firmware. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+201 | 4/7/2023 | 17/6/2026 | Memory Corruption in Audio while allocating the ion buffer during the music playback. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+267 | 4/7/2023 | 17/6/2026 | Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+197 | 4/7/2023 | 17/6/2026 | Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+51 | 4/7/2023 | 17/6/2026 | Memory corruption in Linux while calling system configuration APIs. | |
| Modificada | Alta (7.8) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Csrb31024 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6800 Firmware+45 | 4/7/2023 | 17/6/2026 | Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony. | |
| Modificada | Crítica (9.8) | 0.36% | — | Qualcomm 315 5G FirmwareQualcomm 9205 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 Firmware+156 | 4/7/2023 | 17/6/2026 | Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. | |
| Modificada | Media (6.8) | 0.19% | — | Qualcomm 315 5G FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 Firmware+208 | 4/7/2023 | 17/6/2026 | Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | |
| Modificada | Alta (7.8) | 0.35% | — | Autodesk 3DS MAXAutodesk NavisworksAutodesk RevitAutodesk Vred | 27/6/2023 | 17/6/2026 | A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Alta (7.8) | 0.26% | — | Autodesk Navisworks | 27/6/2023 | 17/6/2026 | A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk AliasAutodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad Architecture+13 | 27/6/2023 | 17/6/2026 | A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. |