Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

5409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.9)0.85%—Fit2cloud JumpserverFit2cloud Koko16/3/202317/6/2026
Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to a Kubernetes cluster through Koko can result in the execution of dangerous…
ModificadaMedia (6.5)0.60%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK15/3/202317/6/2026
IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032.
ModificadaMedia (6.5)0.50%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK15/3/202317/6/2026
IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.
ModificadaCrítica (9.8)0.84%—Ubikasec Waap CloudUbikasec Waap Gateway8/3/202317/6/2026
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.
ModificadaCrítica (9.8)0.86%—Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS16/3/202317/6/2026
Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22336 vulnerabilities together,…
ModificadaCrítica (9.8)1.1%—Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS16/3/202317/6/2026
Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22344 vulnerabilities together, it may…
ModificadaAlta (7.5)0.74%—Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS16/3/202317/6/2026
Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to bypass access restriction and download an arbitrary file of the directory where the product runs. As a result of exploiting this vulnerability with CVE-2023-22336 and…
ModificadaMedia (5.3)7.0%💥 PoCCisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security1/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.…
ModificadaCrítica (9.8)29%—Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+11/3/202317/6/2026
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability…
ModificadaMedia (4.3)0.80%—Nextcloud Talk27/2/202317/6/2026
Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. It is recommended that the Nextcloud Talk is upgraded to 15.0.3. There are no…
ModificadaMedia (5.4)0.39%—IBM Cloud PAK FOR Business Automation27/2/202317/6/2026
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…
ModificadaAlta (7.5)0.95%—Nextcloud Server25/2/202317/6/2026
Nextcloud es un software de nube privada de código abierto. Las versiones 24.0.4 y posteriores, anteriores a la 24.0.7, y 25.0.0 y posteriores, anteriores a la 25.0.1, contienen control de acceso inadecuado. La vista segura de recursos compartidos internos se puede eludir si también se otorgan permisos para compartir.…
ModificadaMedia (6.5)1.4%—Nextcloud Server25/2/202317/6/2026
Nextcloud es un software de nube privada de código abierto. Las versiones 25.0.0 y superiores, anteriores a la 25.0.3, están sujetas al Consumo Incontrolado de Recursos. Un usuario puede configurar una contraseña muy larga, consumiendo más recursos de los deseados en la validación de contraseña. Este problema se…
ModificadaAlta (8.8)0.36%—Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller23/2/202317/6/2026
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This…
ModificadaAlta (8.8)0.26%—Quantumcloud Chatbot23/2/202317/6/2026
Vulnerabilidad Cross-Site Request Forgery (CSRF) en versiones 4.2.8 y anteriores del plugin QuantumCloud ChatBot ?.
ModificadaAlta (7.5)0.51%—Nextcloud Server22/2/202317/6/2026
Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and normalizing the string in the wrong order. The function is used in the `newFile()` and `newFolder()` items, which may allow to creation of paths outside of ones own space and…
ModificadaCrítica (9.8)0.71%—Hybridsoftware Cloudflow22/2/202317/6/2026
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.
AnalizadaMedia (6.5)0.63%—Hybridsoftware Cloudflow22/2/202317/6/2026
Una vulnerabilidad de inclusión de archivos locales dentro de Cloudflow permite a los atacantes recuperar información confidencial del sistema.
ModificadaMedia (6.1)0.53%—Nhncloud Toast UI Chart22/2/202317/6/2026
Se ha encontrado una vulnerabilidad clasificada como problemática en NHN TOAST UI Gráfico 4.1.4. Este problema afecta un procesamiento desconocido del componente Legend Handler. La manipulación conduce a cross-site scripting. El ataque puede iniciarse de forma remota. La actualización a la versión 4.2.0 puede…
ModificadaMedia (5.3)0.32%—Splunk Add-on BuilderSplunk Cloudconnect Software Development KIT14/2/202317/6/2026
In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectly revert to using HTTP to connect after a failure to connect over HTTPS occurs.
ModificadaAlta (7.5)1.0%💥 PoCSplunkSplunk Cloud Platform14/2/202317/6/2026
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).
ModificadaMedia (5.7)0.43%—SplunkSplunk Cloud Platform14/2/202317/6/2026
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryindex’, ‘sumindex’, ‘stash’,’ mcollect’, and ‘meventcollect’, were not designated as safeguarded commands. The commands could potentially allow for the exposing of data to…
ModificadaAlta (8.8)0.59%—SplunkSplunk Cloud Platform14/2/202317/6/2026
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.
ModificadaMedia (4.3)0.36%—SplunkSplunk Cloud Platform14/2/202317/6/2026
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.
ModificadaMedia (4.3)0.41%—SplunkSplunk Cloud Platform14/2/202317/6/2026
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup tables with unnecessary filename extensions. Lookup table file extensions may now be one of the following only: .csv, .csv.gz, .kmz, .kml, .mmdb, or .mmdb.gzl.