Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.68% | — | Switchwp WP Client Reports | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions. | |
| Modificada | Alta (8.8) | 0.29% | — | Jamesmehorter Device Theme Switcher | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in James Mehorter Device Theme Switcher.This issue affects Device Theme Switcher: from n/a through 3.0.2. | |
| Modificada | Media (5.4) | 0.44% | — | Plugin-planet Theme Switcha | 20/10/2023 | 17/6/2026 | The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list' shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.5) | 0.78% | — | Tapo Mini Smart Wi-fi Plug FirmwareNanoleaf Lightstrip FirmwareGovee LED Strip FirmwareSwitchbot Hub2 Firmware+5 | 10/10/2023 | 17/6/2026 | Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a… | |
| Modificada | Media (5.5) | 0.42% | — | OpenvswitchRedhat Openshift Container PlatformRedhat VirtualizationRedhat Enterprise Linux+1 | 6/10/2023 | 17/6/2026 | A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses. | |
| Modificada | Alta (8.8) | 0.25% | — | Fugu Maintenance Switch | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fugu Maintenance Switch plugin <= 1.5.2 versions. | |
| Modificada | Media (6.5) | 0.91% | — | Freeswitch | 15/9/2023 | 17/6/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP… | |
| Modificada | Alta (7.5) | 0.99% | — | Freeswitch | 15/9/2023 | 17/6/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown… | |
| Modificada | Media (4.3) | 0.66% | — | Ericsson Mobile Switching Center Server BC 18A Firmware | 14/9/2023 | 17/6/2026 | In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application. | |
| Modificada | Media (4.3) | 0.50% | — | Fortinet Fortiswitchmanager | 7/9/2023 | 17/6/2026 | An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API. | |
| Modificada | Alta (8.8) | 0.26% | — | Startrinity Softswitch | 3/9/2023 | 17/6/2026 | StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352) | |
| Modificada | Media (6.1) | 0.36% | — | Startrinity Softswitch | 3/9/2023 | 17/6/2026 | StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601) | |
| Modificada | Media (5.4) | 0.38% | — | Startrinity Softswitch | 3/9/2023 | 17/6/2026 | StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79) | |
| Modificada | Media (6.1) | 0.40% | — | Startrinity Softswitch | 3/9/2023 | 17/6/2026 | StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79) | |
| Modificada | Crítica (9.8) | 0.83% | — | HPE Arubaos-switch | 29/8/2023 | 17/6/2026 | A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | |
| Modificada | Media (6.5) | 0.83% | — | HPE Arubaos-switch | 29/8/2023 | 17/6/2026 | An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Denial-of-Service (DoS) condition in the switch. | |
| Modificada | Media (6.1) | 0.52% | — | HPE Arubaos-switch | 29/8/2023 | 17/6/2026 | A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary… | |
| Modificada | Crítica (9.8) | 1.4% | — | UI Unifi UAP FirmwareUI Unifi Switch Firmware | 10/8/2023 | 17/6/2026 | A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini… | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | UI Unifi UAP FirmwareUI Unifi Switch Firmware | 10/8/2023 | 17/6/2026 | An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All UniFi Switches (Version 6.5.32 and earlier)… | |
| Modificada | Media (5.5) | 0.11% | — | Samsung Smart Switch PC | 6/7/2023 | 17/6/2026 | Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attackers to delete arbitrary directory using directory junction. | |
| Modificada | Media (5.5) | 0.15% | — | Samsung Smart Switch PC | 6/7/2023 | 17/6/2026 | Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction. | |
| Modificada | Baja (2.7) | 0.64% | — | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet Fortios | 13/6/2023 | 17/6/2026 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and before 7.0.1 allows an privileged attacker to delete… | |
| Modificada | Media (5.4) | 0.36% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcs_current_currency shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Modificada | Media (4.3) | 0.41% | — | Pluginus Wordpress Currency Switcher Professional | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Modificada | Media (4.3) | 0.43% | — | Pluginus Wordpress Currency Switcher | 9/6/2023 | 17/6/2026 | The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the anonymous function for the wpcs_sd_delete action in versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with… |