Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
697 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.43% | — | Zoom Meeting Software Development KITZoom RoomsZoom WorkplaceZoom Workplace Desktop+1 | 15/7/2024 | 17/6/2026 | Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.8) | 0.17% | — | Zoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/7/2024 | 17/6/2026 | Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access. | |
| Analizada | Alta (7.8) | 0.10% | — | Zoom Workplace Virtual Desktop Infrastructure | 15/5/2024 | 17/6/2026 | Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.41% | — | Zoom Meeting Software Development KITZoom WorkplaceZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/5/2024 | 17/6/2026 | Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Baja (3.7) | 0.75% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise… | |
| Analizada | Baja (3.7) | 1.3% | — | Netapp Active IQ Unified ManagerNetapp Data Infrastructure Insights Acquisition UnitNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+5 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows… | |
| Analizada | Baja (3.7) | 1.3% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2 and 22; Oracle GraalVM Enterprise… | |
| Analizada | Baja (3.7) | 0.91% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition:… | |
| Analizada | Baja (3.7) | 1.4% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+6 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 21.0.2, 22; Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise… | |
| Analizada | Baja (3.1) | 0.85% | — | Oracle GraalvmOracle JDKOracle JRENetapp Active IQ Unified Manager+4 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Analizada | Baja (2.5) | 0.35% | — | Oracle GraalvmOracle JDKOracle JRENetapp Active IQ Unified Manager+4 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with logon to… | |
| Modificada | Baja (3.1) | 0.86% | — | Oracle GraalvmOracle JDKOracle JRENetapp Active IQ Unified Manager+4 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Analizada | Baja (2.5) | 0.35% | — | Oracle GraalvmOracle JDKOracle JRENetapp Active IQ Unified Manager+4 | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u401; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with logon to… | |
| Analizada | Crítica (9.8) | 20% | — | Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+1 | 5/2/2024 | 17/6/2026 | A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. | |
| Analizada | Alta (7.5) | 1.1% | — | Redhat Enterprise LinuxRedhat Update InfrastructureM2crypto Project M2crypto | 5/2/2024 | 16/9/2026 | A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. | |
| Modificada | Media (6.5) | 0.55% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 17/1/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters.… | |
| Modificada | Media (6.7) | 0.18% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 17/1/2024 | 17/6/2026 | A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit… | |
| Modificada | Alta (7.2) | 0.69% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 17/1/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could… | |
| Modificada | Media (4.8) | 0.36% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 17/1/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this… | |
| Modificada | Alta (7.4) | 0.32% | — | Oracle Financial Services Analytical Applications Infrastructure | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows low privileged attacker with… | |
| Modificada | Alta (7.8) | 0.25% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoomZoom Virtual Desktop Infrastructure | 12/1/2024 | 17/6/2026 | Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.40% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom | 13/12/2023 | 17/6/2026 | Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. | |
| Modificada | Alta (8.8) | 0.99% | — | Zoom Meeting Software Development KITZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom | 13/12/2023 | 17/6/2026 | Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Modificada | Media (6.5) | 0.65% | — | Zoom MeetingsZoom Virtual Desktop InfrastructureZoom | 15/11/2023 | 17/6/2026 | Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. |