Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 704 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
4540 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Woocommerce Automatewoo | 28/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Woocommerce Automatewoo | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions. | |
| Modificada | Alta (7.2) | 0.91% | — | Autolabproject Autolab | 26/5/2023 | 17/6/2026 | Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the Install assessment functionality of Autolab. To exploit this vulnerability an authenticated attacker with instructor permissions needs to upload a specially crafted Tar file. Using the… | |
| Modificada | Alta (7.2) | 0.89% | — | Autolabproject Autolab | 26/5/2023 | 17/6/2026 | Autolab is a course management service that enables auto-graded programming assignments. A Tar slip vulnerability was found in the MOSS cheat checker functionality of Autolab. To exploit this vulnerability an authenticated attacker with instructor permissions needs to upload a specially crafted Tar file. Both "Base… | |
| Modificada | Crítica (9.8) | 0.62% | — | Ipekyolunet Software Auto Damage Tracking Software | 24/5/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4. | |
| Modificada | Alta (8.8) | 0.26% | — | Secondlinethemes Auto Youtube Importer | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <= 1.0.3 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Flamescorpion Auto Affiliate Links | 20/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Mijnpress Auto Prune Posts | 18/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Auto Prune Posts plugin <= 1.8.0 versions. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk 3DS MAX USD | 12/5/2023 | 17/6/2026 | A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds write vulnerability which could result in code execution. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk 3DS MAX USD | 12/5/2023 | 17/6/2026 | A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution. | |
| Modificada | Alta (7.8) | 0.23% | — | Autodesk 3DS MAX USD | 12/5/2023 | 17/6/2026 | A malicious actor may convince a user to open a malicious USD file that may trigger an uninitialized pointer which could result in code execution. | |
| Modificada | Alta (7.8) | 0.24% | — | Autodesk 3DS MAX USD | 12/5/2023 | 17/6/2026 | A malicious actor may convince a user to open a malicious USD file that may trigger a use-after-free vulnerability which could result in code execution. | |
| Modificada | Alta (7.8) | 0.22% | — | Autodesk Infraworks | 12/5/2023 | 17/6/2026 | A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability. | |
| Modificada | Alta (8.8) | 0.38% | — | Rockwellautomation Factorytalk Vantagepoint | 11/5/2023 | 17/6/2026 | A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could… | |
| Modificada | Alta (7.5) | 0.67% | — | Rockwellautomation Thinmanager | 11/5/2023 | 17/6/2026 | Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API. | |
| Modificada | Crítica (9.1) | 1.3% | — | Rockwellautomation Kinetix 5500 Firmware | 11/5/2023 | 17/6/2026 | Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized access to the device through the open ports. | |
| Modificada | Alta (7.1) | 0.49% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. | |
| Modificada | Alta (7.1) | 0.49% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (5.9) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the… | |
| Modificada | Media (6.5) | 0.62% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discovered that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is… | |
| Modificada | Media (6.1) | 0.49% | — | Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware | 11/5/2023 | 17/6/2026 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. |