Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2306 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.16% | — | UI Unifi ProtectAI | 1/3/2025 | 17/6/2026 | An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system. | |
| Aplazada | Media (6.8) | 0.24% | — | UI Unifi ProtectAI | 1/3/2025 | 17/6/2026 | An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system. | |
| Aplazada | Crítica (9.6) | 0.51% | — | UI Unifi ProtectAI | 1/3/2025 | 17/6/2026 | An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Protect Cameras adjacent network to take control of UniFi Protect Cameras. | |
| Aplazada | Crítica (9) | 0.72% | — | UI Unifi ProtectAI | 1/3/2025 | 17/6/2026 | A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras management network. | |
| Analizada | Crítica (9.8) | 0.54% | — | Changeweb Unifiedtransform | 26/2/2025 | 17/6/2026 | Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}. | |
| Modificada | Alta (7.7) | 0.39% | — | Netapp Active IQ Unified ManagerNetapp Manageability Software Development KITNetapp OntapNetapp Solidfire & HCI Management Node+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047. | |
| Modificada | Crítica (9.8) | 1.2% | — | Xmlsoft Libxml2Netapp HCI Compute NodeNetapp H410c FirmwareNetapp H300s Firmware+7 | 18/2/2025 | 17/6/2026 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used. | |
| Modificada | Media (6.8) | 7.7% | 💥 PoC | Openbsd OpensshNetapp Active IQ Unified ManagerNetapp OntapRedhat Openshift Container Platform+2 | 18/2/2025 | 2/9/2026 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be… | |
| Aplazada | Crítica (9.8) | 0.90% | — | Alvaria Unified IP Unified DirectorAI | 14/2/2025 | 17/6/2026 | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component. | |
| Analizada | Crítica (9.8) | 75% | — | Logsign Unified Secops Platform | 11/2/2025 | 17/6/2026 | Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which… | |
| Analizada | Baja (2.3) | 0.72% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 11/2/2025 | 17/6/2026 | A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The… | |
| Analizada | Media (6.3) | 0.80% | — | GNU BinutilsNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility | 11/2/2025 | 17/6/2026 | A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The… | |
| Analizada | Alta (7.5) | 2.2% | — | NettyNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 10/2/2025 | 17/6/2026 | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.… | |
| Aplazada | Media (5.9) | 0.20% | — | UI Unifi OSAI | 1/2/2025 | 17/6/2026 | An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update. | |
| Aplazada | Media (5.5) | 0.20% | — | Nvidia Unified Memory Driver FOR LinuxAI | 28/1/2025 | 17/6/2026 | NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Alta (7) | 67% | ⚠ Explotación activa💥 PoC | Netapp Active IQ Unified Manager7-zip | 25/1/2025 | 17/6/2026 | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific… | |
| Analizada | Media (4.8) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+7 | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM… | |
| Analizada | Media (4.9) | 0.96% | — | Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation | 21/1/2025 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Analizada | Baja (2.1) | 3.2% | 💥 Exploit | Apache Nifi | 28/12/2024 | 17/6/2026 | Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter Context, but in cases where the Process Group… | |
| Aplazada | Alta (7) | 0.18% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic Step 7 SafetyAISiemens Simatic WinccAI+8 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4), SIMATIC STEP 7 V17 (All versions < V17 Update… | |
| Aplazada | Alta (8.4) | 0.22% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+7 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4),… | |
| Aplazada | Media (4.3) | 0.24% | — | Changeweb UnifiedtransformAI | 9/12/2024 | 17/6/2026 | A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows teachers to modify student personal data without proper authorization. The vulnerability exists due to missing access control checks in the student editing functionality. At the time of publication of… | |
| Aplazada | Media (4.3) | 0.26% | — | Changeweb UnifiedtransformAI | 9/12/2024 | 17/6/2026 | Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both function-level access control issues in list viewing endpoints and object-level access control issues in… | |
| Aplazada | Media (4.3) | 0.26% | — | Changeweb UnifiedtransformAI | 9/12/2024 | 17/6/2026 | An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerability exists due to… | |
| Aplazada | Alta (7.1) | 0.13% | — | UI Unifi IOS APPAI | 4/12/2024 | 17/6/2026 | An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point. Affected Products: UniFi iOS App (Version 10.17.7 and earlier) Mitigation:… |