Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
474 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 17% | — | Bravenewcode Wptouch | 9/1/2023 | 17/6/2026 | The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | |
| Modificada | Alta (7.5) | 47% | 💥 Exploit | Aveva Intouch Access Anywhere | 23/12/2022 | 17/6/2026 | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server. | |
| Modificada | Media (4.7) | 0.26% | 💥 PoC | Lenovo Elan Miniport Touchpad Driver | 7/11/2022 | 17/6/2026 | ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice. | |
| Modificada | Alta (7.8) | 0.47% | 💥 PoC | Ubports Ubuntu Touch | 9/9/2022 | 17/6/2026 | UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user account's password. NOTE: a third party states "The described attack cannot be executed as demonstrated. | |
| Modificada | Media (4.8) | 0.61% | — | Mtouch Quiz Project Mtouch Quiz | 8/8/2022 | 17/6/2026 | The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.5) | 0.96% | — | Couchbase Server | 21/7/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes. | |
| Modificada | Media (5.9) | 0.63% | — | Couchbase Server | 15/7/2022 | 17/6/2026 | In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs. | |
| Modificada | Media (5.3) | 1.0% | — | Couchbase Server | 12/7/2022 | 17/6/2026 | An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information. | |
| Modificada | Alta (7.5) | 1.2% | — | Couchbase Server | 12/7/2022 | 17/6/2026 | An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection to determine the TLS port number, using SCRAM-SHA instead. | |
| Modificada | Alta (7.5) | 0.89% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+15 | 11/7/2022 | 17/6/2026 | In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. | |
| Modificada | Alta (7.5) | 0.89% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+15 | 11/7/2022 | 17/6/2026 | In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected. | |
| Modificada | Alta (7.8) | 0.78% | — | Fujielectric Monitouch V-sft | 16/6/2022 | 17/6/2026 | Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | |
| Modificada | Alta (7.8) | 0.78% | — | Fujielectric Monitouch V-sft | 16/6/2022 | 17/6/2026 | Out-of-bounds write vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file. | |
| Modificada | Media (4.9) | 0.81% | — | Couchbase Server | 14/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network. | |
| Modificada | Crítica (9.1) | 1.3% | — | Couchbase Server | 14/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics. | |
| Modificada | Alta (7.5) | 1.1% | — | Couchbase Server | 14/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers. | |
| Modificada | Alta (7.5) | 1.1% | — | Couchbase Server | 13/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids. | |
| Modificada | Alta (8.8) | 0.96% | — | Couchbase Server | 13/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission. | |
| Modificada | Alta (7.5) | 0.93% | — | Couchbase Server | 13/6/2022 | 17/6/2026 | Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor. | |
| Modificada | Alta (7.5) | 1.1% | — | Couchbase Server | 13/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie. | |
| Modificada | Alta (7.5) | 1.0% | — | Couchbase Server | 13/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings. | |
| Modificada | Alta (7.5) | 1.2% | — | Couchbase Server | 13/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure. | |
| Modificada | Media (6.5) | 0.73% | — | Couchbase Server | 13/6/2022 | 17/6/2026 | Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor. | |
| Modificada | Crítica (9.8) | 0.81% | — | Couchbase Sync Gateway | 10/6/2022 | 17/6/2026 | An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509 client certificates, the admin credentials… | |
| Modificada | Alta (8.8) | 0.99% | — | Deltacontrols Entelitouch Firmware | 2/6/2022 | 17/6/2026 | Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request. |