Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

2202 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.31%—IBM Cognos AnalyticsIBM Cognos Transformer27/5/202617/6/2026
IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead…
AnalizadaCrítica (9.8)0.36%—IBM Operations Analytics LOG Analysis27/5/202617/6/2026
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to…
AnalizadaMedia (4.3)0.17%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Las versiones de Hitachi Vantara Pentaho Data Integration & Analytics anteriores a la 10.2.0.6 y 11.0.0.0, incluyendo las 9.3.x y 8.3.x, exponen las credenciales del clúster de Hadoop en texto plano a través de la API de prueba del clúster. Aunque el usuario no debería verlas explícitamente, el defecto se mitiga por…
AnalizadaMedia (6.3)0.15%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Hitachi Vantara Pentaho Data Integration & Analytics versiones anteriores a la 10.2.0.6 y 11.0.0.0, incluyendo las 9.3.x y 8.3.x, no aplica ACLs en ciertos endpoints de la API relacionados con las notificaciones de correo de la plataforma.
AnalizadaAlta (7.7)0.20%—Hitachi Vantara Pentaho Data Integration AND Analytics27/5/202624/7/2026
Las versiones de Hitachi Vantara Pentaho Data Integration & Analytics anteriores a 10.2.0.7 y 11.0.0.0, incluyendo 9.3.x y 8.3.x, no impiden que ciertos analizadores XML resuelvan entidades externas.
AplazadaBaja (2.1)0.42%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI26/5/202624/7/2026
Se ha identificado una debilidad en SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Esto afecta a una función desconocida del archivo /index.php del componente SQL Gestor. La ejecución de una manipulación puede llevar a la exposición de información a través de un mensaje de error. El…
AplazadaBaja (2.1)0.23%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI26/5/202624/7/2026
Se ha descubierto un fallo de seguridad en SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Esto afecta a una función desconocida. Realizar una manipulación resulta en falsificación de petición en sitios cruzados. El ataque es posible de llevar a cabo remotamente. El exploit ha sido…
AnalizadaAlta (7.6)0.18%—IBM Cognos AnalyticsIBM Cognos Transformer26/5/202624/7/2026
IBM Cognos Analytics 11.2.0, 12.0, y 12.1.0 e IBM Cognos Transformer 12.0, 11.2.4, y 12.1.0 son vulnerables a cross-site scripting (XSS) almacenado en la Administración de Cognos. Esta vulnerabilidad permite a un usuario privilegiado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así…
AplazadaMedia (4.6)0.20%—Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI26/5/202624/7/2026
Vulnerabilidad por falta de enmascaramiento del campo de contraseña en Hitachi Ops Center Analyzer (vista de detalles de Hitachi Ops Center Analyzer, módulos de sonda de Hitachi Ops Center Analyzer), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Análisis de centros de datos, módulos…
AplazadaMedia (5.3)0.29%—Cornelraiu WP Search AnalyticsAI25/5/202624/7/2026
Vulnerabilidad por falta de autorización en Cornel Raiu WP Search Analytics permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a WP Search Analytics: desde n/a antes de 1.5.0.
AnalizadaAlta (8.6)0.14%—Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+1125/5/202617/8/2026
La inserción de información sensible en el archivo de registro (CWE-532) en algunos instaladores del Servicio Command Centre podría llevar a la exposición de las credenciales de la cuenta de servicio. Factor de mitigación: Solo los sitios que instalan los Servicios Command Centre con una cuenta de servicio…
AplazadaMedia (5.9)0.39%—ElasticsearchAIMicrosoft Office Open XMLAI19/5/202617/6/2026
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
Pendiente de análisisMedia (6.8)0.22%—Dell Live OpticsAI18/5/202617/6/2026
Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
AplazadaCrítica (9.3)0.58%—ACL AnalyticsAI17/5/202617/6/2026
ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse…
AplazadaCrítica (9.8)3.0%💥 ExploitBurst-statistics Burst StatisticsAI14/5/202617/6/2026
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the…
AnalizadaAlta (7.1)0.28%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202617/6/2026
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information. Note: Software versions which have reached End of Technical Support (EoTS) are…
En análisisAlta (8.5)0.58%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.5)0.41%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.46%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (7.1)0.42%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (7.1)0.27%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202623/6/2026
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.46%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+1913/5/202623/6/2026
When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.7)0.11%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202623/6/2026
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.5)0.25%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1813/5/202623/6/2026
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.9)0.40%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202623/6/2026
A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.