Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

438 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.54%—Redhat MRG Management Console30/12/201916/6/2026
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
ModificadaAlta (8.8)1.2%—Consolekit Project ConsolekitDebian LinuxRedhat Enterprise Linux13/11/201916/6/2026
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaAlta (7.8)0.34%—Intel Active System Console11/10/201917/6/2026
Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.30%—Vmware HorizonVmware Remote ConsoleVmware WorkstationVmware Fusion+110/10/201917/6/2026
ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.
ModificadaAlta (7.3)28%—Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+5620/8/201925/8/2026
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
ModificadaAlta (7.6)0.79%—Intel Raid WEB Console 219/8/201917/6/2026
Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attacker to potentially enable disclosure of information via network access.
ModificadaMedia (6.3)0.97%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (7.2)1.4%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (7.3)1.6%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (8.8)1.6%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaMedia (4.8)0.55%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaCrítica (9.4)4.3%—HP 3par Storeserv Management Console9/8/201917/6/2026
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
ModificadaAlta (7.8)3.9%💥 ExploitCastlerock Simple Network Management Protocol Console12/7/201917/6/2026
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file.
ModificadaCrítica (9.8)1.2%—Checkpoint Jumbo Hotfix FOR Endpoint Security ServerCheckpoint Endpoint Security Server PackageCheckpoint Smartconsole FOR Endpoint Security ServerCheckpoint Endpoint Security Clients+220/6/201917/6/2026
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
ModificadaCrítica (9.8)2.0%—Intel Raid WEB Console 313/6/201917/6/2026
Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (8.1)4.5%—Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+108/5/201917/6/2026
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
ModificadaAlta (8.1)5.1%—Linux KernelCanonical Ubuntu LinuxDebian LinuxF5 Traffix Signaling Delivery Controller+97/5/201917/6/2026
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
ModificadaAlta (7.7)4.3%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+1025/4/201917/6/2026
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net…
ModificadaMedia (5.5)0.54%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+924/4/201917/6/2026
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial…
ModificadaAlta (7)0.37%—Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ+623/4/201917/6/2026
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.
ModificadaMedia (5.3)5.9%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+2222/4/201917/6/2026
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.…
ModificadaMedia (5.3)4.1%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+2122/4/201917/6/2026
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in…
ModificadaMedia (4.7)0.34%—Linux KernelDebian LinuxNetapp Active IQ Unified Manager FOR Vmware VsphereNetapp HCI Management Node+622/4/201917/6/2026
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before…
ModificadaMedia (6.1)1.5%—Oracle Java Advanced Management Console16/1/201917/6/2026
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java…
Orbitaley — Vulnerabilidades