Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 702 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
5409 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.38% | — | SplunkSplunk Cloud Platform | 14/2/2023 | 17/6/2026 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment. | |
| Modificada | Alta (8.8) | 0.61% | — | SplunkSplunk Cloud Platform | 14/2/2023 | 17/6/2026 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk… | |
| Modificada | Alta (8) | 1.1% | — | SplunkSplunk Cloud Platform | 14/2/2023 | 17/6/2026 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request… | |
| Modificada | Media (6.1) | 0.83% | — | SplunkSplunk Cloud Platform | 14/2/2023 | 17/6/2026 | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) View through the ‘layoutPanel’ attribute in the ‘module’ tag’. | |
| Modificada | Media (6.1) | 0.40% | — | SplunkSplunk Cloud Platform | 14/2/2023 | 17/6/2026 | In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The vulnerability affects instances with Splunk Web enabled. It does not affect Splunk Enterprise versions below 9.0. | |
| Modificada | Media (4.3) | 0.36% | — | SplunkSplunk Cloud Platform | 14/2/2023 | 17/6/2026 | In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resource Description Format Site Summary (RSS) feeds without verifying permissions. This feature has been deprecated and disabled by default. | |
| Modificada | Media (5.3) | 0.82% | — | Nextcloud Server | 13/2/2023 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to 24.0.8 and 23.0.12 and Nextcloud Enterprise server prior to 24.0.8 and 23.0.12 are vulnerable to server-side request forgery (SSRF). Attackers can leverage enclosed alphanumeric payloads to bypass… | |
| Modificada | Media (5.3) | 0.73% | — | Nextcloud Server | 13/2/2023 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact… | |
| Modificada | Media (5.3) | 0.46% | — | Nextcloud Mail | 13/2/2023 | 17/6/2026 | Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail… | |
| Modificada | Media (5.3) | 0.46% | — | Nextcloud ServerNextcloud Richdocuments | 13/2/2023 | 17/6/2026 | Nextcloud Server es el software de servidor de archivos para Nextcloud, una plataforma de productividad autohospedada, y Nextcloud Office es una aplicación de colaboración de documentos para la misma plataforma. Nextcloud Server 24.0.x anterior a 24.0.8 y 25.0.x anterior a 25.0.1, Nextcloud Enterprise Server 24.0.x… | |
| Analizada | Media (4.4) | 0.52% | — | Owncloud Client | 13/2/2023 | 17/6/2026 | La aplicación ownCloud para Android permite a los usuarios de ownCloud acceder, compartir y editar archivos y carpetas. Antes de la versión 3.0, la aplicación tenía una solución incompleta para un problema de Path Traversal y era vulnerable a dos métodos de omisión. Las omisiones pueden dar lugar a la divulgación de… | |
| Modificada | Media (5.5) | 0.46% | — | Owncloud Client | 13/2/2023 | 17/6/2026 | La aplicación ownCloud para Android permite a los usuarios de ownCloud acceder, compartir y editar archivos y carpetas. La versión 2.21.1 de la aplicación ownCloud para Android es vulnerable a la inyección SQL en `FileContentProvider.kt`. Este problema puede dar lugar a la divulgación de información. Dos bases de… | |
| Modificada | Crítica (9.8) | 0.86% | — | IBM Watson Knowledge Catalog ON Cloud PAK FOR Data | 12/2/2023 | 17/6/2026 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.5.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 237402. | |
| Modificada | Baja (3.3) | 0.20% | — | Samsung Cloud | 9/2/2023 | 17/6/2026 | Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file. | |
| Modificada | Baja (3.3) | 0.15% | — | Samsung Cloud | 9/2/2023 | 17/6/2026 | Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent. | |
| Modificada | Media (5.7) | 0.73% | — | Nextcloud Richdocuments | 8/2/2023 | 17/6/2026 | Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the content of other users files. It is… | |
| Modificada | Alta (8.8) | 0.53% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 8/2/2023 | 17/6/2026 | IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210. | |
| Modificada | Media (4.3) | 0.92% | — | Nextcloud Mail | 6/2/2023 | 17/6/2026 | Nextcloud mail es una aplicación de correo electrónico para la plataforma de servidor doméstico nextcloud. En las versiones afectadas, los campos de host SMTP, IMAP y Sieve permitían escanear servicios internos y servidores accesibles desde la red local del servidor Nextcloud. Se recomienda actualizar la aplicación… | |
| Modificada | Media (6.1) | 0.68% | — | Nextcloud Desktop | 6/2/2023 | 17/6/2026 | Nextcloud Desktop Client es una herramienta para sincronizar archivos desde un servidor Nextcloud con su computadora. A las versiones anteriores a la 3.6.3 les falta desinfección en las etiquetas qml que se utilizan para elementos HTML básicos como las líneas `strong`, `em` y `head` en la interfaz de usuario del… | |
| Modificada | Media (6.5) | 0.47% | — | Nextcloud Mail | 6/2/2023 | 17/6/2026 | Nextcloud mail is an email app for the nextcloud home server platform. In versions prior to 2.2.2 user's passwords were stored in cleartext in the database during the duration of OAuth2 setup procedure. Any attacker or malicious user with access to the database would have access to these user passwords until the OAuth… | |
| Modificada | Crítica (9.8) | 0.81% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files. | |
| Modificada | Alta (8.8) | 1.0% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation. | |
| Modificada | Crítica (9.8) | 1.2% | — | Westerndigital MY Cloud OS | 6/2/2023 | 17/6/2026 | Western Digital My Cloud devices before OS5 have a nobody account with a blank password. | |
| Modificada | Crítica (9.1) | 0.38% | — | Cloudfoundry Cf-deploymentCloudfoundry Diego | 3/2/2023 | 17/6/2026 | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are turned off, then an attacker could… | |
| Modificada | Baja (3.3) | 0.18% | — | IBM Cloud PAK FOR Business Automation | 1/2/2023 | 17/6/2026 | IBM ICP4A - Automation Decision Services 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 244504. |