Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
438 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.54% | — | Redhat MRG Management Console | 30/12/2019 | 16/6/2026 | An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it. | |
| Modificada | Alta (8.8) | 1.2% | — | Consolekit Project ConsolekitDebian LinuxRedhat Enterprise Linux | 13/11/2019 | 16/6/2026 | In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel Active System Console | 11/10/2019 | 17/6/2026 | Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.30% | — | Vmware HorizonVmware Remote ConsoleVmware WorkstationVmware Fusion+1 | 10/10/2019 | 17/6/2026 | ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5. | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Alta (7.6) | 0.79% | — | Intel Raid WEB Console 2 | 19/8/2019 | 17/6/2026 | Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attacker to potentially enable disclosure of information via network access. | |
| Modificada | Media (6.3) | 0.97% | — | HP 3par Storeserv Management Console | 9/8/2019 | 17/6/2026 | A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | |
| Modificada | Alta (7.2) | 1.4% | — | HP 3par Storeserv Management Console | 9/8/2019 | 17/6/2026 | A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | |
| Modificada | Alta (7.3) | 1.6% | — | HP 3par Storeserv Management Console | 9/8/2019 | 17/6/2026 | A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | |
| Modificada | Alta (8.8) | 1.6% | — | HP 3par Storeserv Management Console | 9/8/2019 | 17/6/2026 | A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | |
| Modificada | Media (4.8) | 0.55% | — | HP 3par Storeserv Management Console | 9/8/2019 | 17/6/2026 | A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | |
| Modificada | Crítica (9.4) | 4.3% | — | HP 3par Storeserv Management Console | 9/8/2019 | 17/6/2026 | A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | |
| Modificada | Alta (7.8) | 3.9% | 💥 Exploit | Castlerock Simple Network Management Protocol Console | 12/7/2019 | 17/6/2026 | nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file. | |
| Modificada | Crítica (9.8) | 1.2% | — | Checkpoint Jumbo Hotfix FOR Endpoint Security ServerCheckpoint Endpoint Security Server PackageCheckpoint Smartconsole FOR Endpoint Security ServerCheckpoint Endpoint Security Clients+2 | 20/6/2019 | 17/6/2026 | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one. | |
| Modificada | Crítica (9.8) | 2.0% | — | Intel Raid WEB Console 3 | 13/6/2019 | 17/6/2026 | Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (8.1) | 4.5% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+10 | 8/5/2019 | 17/6/2026 | An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup. | |
| Modificada | Alta (8.1) | 5.1% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxF5 Traffix Signaling Delivery Controller+9 | 7/5/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. | |
| Modificada | Alta (7.7) | 4.3% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+10 | 25/4/2019 | 17/6/2026 | An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net… | |
| Modificada | Media (5.5) | 0.54% | — | Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+9 | 24/4/2019 | 17/6/2026 | A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial… | |
| Modificada | Alta (7) | 0.37% | — | Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ+6 | 23/4/2019 | 17/6/2026 | The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions. | |
| Modificada | Media (5.3) | 5.9% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+22 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.… | |
| Modificada | Media (5.3) | 4.1% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+21 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in… | |
| Modificada | Media (4.7) | 0.34% | — | Linux KernelDebian LinuxNetapp Active IQ Unified Manager FOR Vmware VsphereNetapp HCI Management Node+6 | 22/4/2019 | 17/6/2026 | A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Java Advanced Management Console | 16/1/2019 | 17/6/2026 | Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java… |