Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
3277 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.40% | — | Xwiki PRO Macros | 5/12/2025 | 25/9/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote code execution. This vulnerability is fixed in 1.27.1. | |
| Analizada | Media (6.5) | 0.28% | — | Xwiki PRO Macros | 19/11/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched in version 1.27.0. | |
| Aplazada | Crítica (10) | 0.73% | — | Xwiki Remote MacrosAI | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the title in the confluence paste code macro allows remote code execution for any user who can edit any page. The classes parameter is… | |
| Aplazada | Crítica (10) | 0.73% | — | Xwiki Remote MacrosAI | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the ac:type in the ConfluenceLayoutSection macro allows remote code execution for any user who can edit any page The classes parameter is… | |
| Analizada | Crítica (9.8) | 0.79% | — | Xwiki PRO Macros | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote code execution for any user who can edit any page The classes parameter is used… | |
| Analizada | Crítica (9.8) | 1.0% | — | Xwiki PRO Macros | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code execution for any user who can edit any page or who can access the CKEditor… | |
| Analizada | Alta (8.8) | 1.1% | — | Xwiki PRO Macros | 12/8/2024 | 17/6/2026 | Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind of attack. This vulnerability is fixed… | |
| Modificada | Alta (7.8) | 0.24% | — | Apple MAC OS XApple Macos | 14/8/2023 | 17/6/2026 | A type confusion issue was addressed with improved state handling. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to execute arbitrary code with kernel privileges. | |
| Modificada | Crítica (9.8) | 1.4% | — | Apple MAC OS XApple Macos | 23/6/2023 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS Monterey 12.3, Security Update 2022-004 Catalina. A remote user may cause an unexpected app termination or arbitrary code execution | |
| Modificada | Alta (7.8) | 0.22% | — | Apple MAC OS X | 8/5/2023 | 17/6/2026 | This issue was addressed by removing the vulnerable code. This issue is fixed in GarageBand for macOS 10.4.8. An app may be able to gain elevated privileges during the installation of GarageBand. | |
| Modificada | Media (5.5) | 18% | — | Apple MAC OS XApple Macos | 27/2/2023 | 17/6/2026 | A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files. | |
| Modificada | Media (5.4) | 0.75% | — | Stiltsoft Handy Macros FOR Confluence | 4/11/2022 | 17/6/2026 | The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 0.97% | — | Apple MAC OS XApple Macos | 1/11/2022 | 17/6/2026 | A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Security Update 2022-005 Catalina. An archive may be able to bypass Gatekeeper. | |
| Modificada | Alta (7.8) | 0.24% | — | Apple MAC OS XApple Macos | 1/11/2022 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to gain elevated privileges. | |
| Modificada | Alta (7.1) | 0.59% | — | Apple MAC OS XApple Macos | 23/9/2022 | 17/6/2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory. | |
| Modificada | Alta (7.1) | 0.59% | — | Apple MAC OS XApple Macos | 23/9/2022 | 17/6/2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory. | |
| Modificada | Media (5.5) | 0.26% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+1 | 23/9/2022 | 17/6/2026 | An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to access sensitive user information. | |
| Modificada | Crítica (9.1) | 3.5% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+2 | 23/9/2022 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory. | |
| Modificada | Alta (7.1) | 0.59% | — | Apple MAC OS XApple Macos | 23/9/2022 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted Postscript file may result in unexpected app termination or disclosure of process memory. | |
| Modificada | Alta (7.8) | 0.56% | — | Apple MAC OS XApple Macos | 23/9/2022 | 17/6/2026 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Monterey 12.5. An app may be able to gain elevated privileges. | |
| Modificada | Media (6.7) | 1.00% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+2 | 23/9/2022 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app with root privileges may be able to execute arbitrary code with kernel privileges. | |
| Modificada | Alta (7.1) | 0.59% | — | Apple MAC OS XApple Macos | 23/9/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory. | |
| Modificada | Alta (7.8) | 0.27% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+2 | 23/9/2022 | 17/6/2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to gain root privileges. | |
| Modificada | Media (5.5) | 0.25% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+2 | 23/9/2022 | 17/6/2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to leak sensitive user information. | |
| Modificada | Alta (7.8) | 0.29% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+2 | 23/9/2022 | 17/6/2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to execute arbitrary code with kernel privileges. |