Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.8%💥 ExploitNexusfi Opac Easyweb Five3/10/201817/6/2026
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.
ModificadaMedia (5.4)0.68%—Jenkins Maven Artifact Choicelistprovider (nexus)1/8/201817/6/2026
An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows attackers to capture credentials with a known credentials ID stored in…
ModificadaAlta (7.5)1.4%—Electroind Gaugetech Nexus Firmware28/6/201817/6/2026
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.
ModificadaAlta (8.6)2.3%—Cisco Nexus 7000 FirmwareCisco Nexus 5000 FirmwareCisco Firepower 9000 FirmwareCisco Nexus 9000 Firmware+121/6/201817/6/2026
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability exists because the affected software insufficiently validates Cisco Fabric…
ModificadaCrítica (9.8)5.9%—Cisco Nexus 7000 FirmwareCisco Nexus 5000 FirmwareCisco Firepower 9000 FirmwareCisco Nexus 9000 Firmware+120/6/201817/6/2026
A vulnerability in the Cisco Fabric Services (CFS) component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability exists because the affected software insufficiently validates Cisco Fabric Services packet…
ModificadaCrítica (9.8)5.6%—Cisco Nexus 7000 FirmwareCisco Nexus 5000 FirmwareCisco Firepower 9000 FirmwareCisco Nexus 9000 Firmware+120/6/201817/6/2026
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software insufficiently…
ModificadaCrítica (9.8)5.6%—Cisco Nexus 7000 FirmwareCisco Nexus 5000 FirmwareCisco Firepower 9000 FirmwareCisco Nexus 9000 Firmware+120/6/201817/6/2026
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. The vulnerability exists because the affected software insufficiently validates header values in…
ModificadaCrítica (9.8)8.6%—Cisco Nexus 7000 FirmwareCisco Nexus 5000 FirmwareCisco Firepower 9000 FirmwareCisco Nexus 9000 Firmware+120/6/201817/6/2026
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to read sensitive memory content, create a denial of service (DoS) condition, or execute arbitrary code as root. The vulnerability exists because the affected software…
ModificadaMedia (4.8)1.3%—Sonatype Nexus Repository Manager11/6/201817/6/2026
Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.
ModificadaMedia (4.8)0.59%—Google ChromeMozilla FirefoxLG Nexus 54/5/201817/6/2026
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
ModificadaMedia (6.1)1.2%—Sonatype Nexus Repository Manager9/2/201817/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the…
ModificadaMedia (6.1)1.1%—Sonatype Nexus Repository Manager9/2/201817/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File…
ModificadaCrítica (9.8)0.71%—Sonatype Nexus Repository Manager17/12/201717/6/2026
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.
ModificadaMedia (6.1)0.89%—Nexusphp Project Nexusphp15/10/201717/6/2026
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
ModificadaMedia (6.1)1.2%💥 PoCNexusphp Project Nexusphp3/10/201717/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php.
ModificadaMedia (6.1)0.67%—Nexusphp Project Nexusphp18/9/201717/6/2026
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
ModificadaCrítica (9.8)1.1%—Nexusphp Project Nexusphp17/9/201717/6/2026
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.
ModificadaMedia (6.1)0.68%—Nexusphp Project Nexusphp12/9/201717/6/2026
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.
ModificadaMedia (6.1)0.82%—Nexusphp Project Nexusphp7/9/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) cheaters.php or (2) confirm_resend.php.
ModificadaAlta (8.8)0.56%—Nexusphp Project Nexusphp7/9/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.
ModificadaCrítica (9.8)1.1%—Nexusphp31/8/201717/6/2026
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.
ModificadaMedia (6.1)0.65%—Nexusphp31/8/201717/6/2026
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.
ModificadaCrítica (9.8)1.2%—Nexusphp31/8/201717/6/2026
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.
ModificadaMedia (6.1)2.6%💥 ExploitOsnexus Quantastor28/8/201717/6/2026
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript…
ModificadaMedia (5.3)4.7%💥 ExploitOsnexus Quantastor28/8/201717/6/2026
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.