Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.3% | — | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+3 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond… | |
| Modificada | Crítica (9.8) | 13% | — | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+12 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent… | |
| Modificada | Alta (7.5) | 5.4% | 💥 PoC | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+6 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a… | |
| Modificada | Media (6.7) | 0.33% | — | Vmware Vrealize Operations | 18/12/2018 | 17/6/2026 | vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell access may exploit this issue to elevate the privileges to root… | |
| Modificada | Media (4.3) | 1.3% | — | IBM Marketing Operations | 9/11/2018 | 17/6/2026 | IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attacker could send a specially-crafted request to cause an error message to be returned containing the full root path. An attacker could use this information to launch further attacks against the affected… | |
| Modificada | Alta (8.8) | 1.0% | — | Microfocus Operations Bridge | 7/11/2018 | 17/6/2026 | A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge containerized suite versions 2017.11, 2018.02, 2018.05, 2018.08. This vulnerability could allow for information disclosure. | |
| Modificada | Alta (8.8) | 1.1% | — | Pivotal Software Operations Manager | 2/11/2018 | 17/6/2026 | Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator… | |
| Modificada | Alta (8.8) | 1.4% | — | Pivotal Software Operations Manager | 5/10/2018 | 17/6/2026 | Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the configs directly onto disk. A remote user that has gained access to the Operations Manager VM, can… | |
| Modificada | Crítica (9.8) | 2.4% | — | Microfocus Data Center AutomationMicrofocus Hybrid Cloud ManagementMicrofocus Network Operations ManagementMicrofocus Operations Bridge+4 | 30/8/2018 | 17/6/2026 | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02,… | |
| Modificada | Crítica (9.8) | 3.1% | — | Microfocus Data Center AutomationMicrofocus Hybrid Cloud ManagementMicrofocus Network Operations ManagementMicrofocus Operations Bridge+1 | 30/8/2018 | 17/6/2026 | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02,… | |
| Modificada | Media (5.9) | 0.86% | — | Pivotal Software Operations Manager | 11/7/2018 | 17/6/2026 | Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the… | |
| Modificada | Media (6.5) | 0.89% | — | Pivotal Software Operations Manager | 25/6/2018 | 17/6/2026 | Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and knowledge of how to exploit the unpatched vulnerabilities may be able to impact Operations Manager | |
| Modificada | Crítica (9.8) | 7.0% | — | Redislabs RedisDebian LinuxOracle Communications Operations MonitorRedhat Openstack | 17/6/2018 | 17/6/2026 | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking. | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Redislabs RedisDebian LinuxOracle Communications Operations MonitorRedhat Openstack | 17/6/2018 | 17/6/2026 | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows. | |
| Modificada | Alta (8.8) | 2.0% | — | HP Network Operations Management UltimateHP Network Automation | 22/5/2018 | 17/6/2026 | SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injection. | |
| Modificada | Media (6.1) | 1.6% | — | HP Network Operations Management UltimateHP Network Automation | 22/5/2018 | 17/6/2026 | Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow persistent cross-site scripting,… | |
| Modificada | Alta (7.5) | 2.6% | — | HP Operations Orchestration | 2/3/2018 | 17/6/2026 | Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service. | |
| Modificada | Media (5.4) | 0.56% | — | HP Operations Bridge Analytics | 15/2/2018 | 17/6/2026 | A Remote Cross-Site Scripting (XSS) vulnerability in HPE Operations Bridge Analytics version v3.0 was found. | |
| Modificada | Crítica (9.8) | 28% | — | HP Operations Orchestration | 15/2/2018 | 17/6/2026 | A remote code execution vulnerability in HPE Operations Orchestration Community edition and Enterprise edition prior to v10.70 was found. | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Alta (7.8) | 0.50% | — | Vmware Vrealize Operations FOR HorizonVmware Vrealize Operations FOR Published Applications | 5/1/2018 | 17/6/2026 | The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM. | |
| Modificada | Media (5.4) | 0.55% | — | Microfocus Operations Manager I | 21/12/2017 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 86% | 💥 Exploit | Redhat Data GridRedhat Jboss A-mqRedhat Jboss BPM SuiteRedhat Jboss Data Virtualization+11 | 9/11/2017 | 17/6/2026 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat… | |
| Modificada | Crítica (9.8) | 9.8% | — | HP Operations Orchestration | 10/10/2017 | 17/6/2026 | A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely. | |
| Modificada | Crítica (9.8) | 2.6% | — | IBM Operations Analytics Predictive Insights | 29/8/2017 | 17/6/2026 | A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges. IBM X-Force ID: 126873. |