Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—Hashicorp Vault10/6/202017/6/2026
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in…
ModificadaCrítica (9.1)1.1%—Hashicorp Vault23/3/202017/6/2026
HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.
ModificadaMedia (5.3)0.76%—Hashicorp Vault23/3/202017/6/2026
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
ModificadaAlta (7.5)1.7%—Alienvault Open Source Security Information Management27/1/202016/6/2026
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
ModificadaAlta (7.5)1.4%—Hashicorp Vault23/1/202017/6/2026
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
ModificadaAlta (7.8)0.49%—Linux KernelRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Power Little Endian EUSRedhat Enterprise Linux+1425/11/201917/6/2026
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
ModificadaAlta (7.5)0.89%—Jenkins Sourcegear Vault1/10/201917/6/2026
Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
ModificadaBaja (2.4)0.42%—Real-sec BC Vault Firmware12/8/201917/6/2026
On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this…
ModificadaCrítica (9.8)40%💥 ExploitCyberark Enterprise Password Vault8/5/201917/6/2026
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system.
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaCrítica (9.8)1.6%—Photorange Photo Vault Project Photorange Photo Vault23/12/201817/6/2026
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.
ModificadaAlta (8.1)0.93%—Hashicorp Vault5/12/201817/6/2026
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
ModificadaMedia (5.4)0.60%—Vaultize Enterprise File Sharing25/4/201817/6/2026
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a different user, who can modify the HTML in that mail before sending it.
ModificadaMedia (5.4)0.63%—Vaultize Enterprise File Sharing25/4/201817/6/2026
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value.
ModificadaMedia (5.3)1.0%—Vaultize Enterprise File Sharing25/4/201817/6/2026
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie.
ModificadaMedia (5.3)1.0%—Vaultize Enterprise File Sharing25/4/201817/6/2026
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.
ModificadaMedia (5.4)0.60%—Vaultize Enterprise File Sharing25/4/201817/6/2026
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download pop-up via a crafted file or folder name.
ModificadaMedia (6.1)0.78%—Vaultize Enterprise File Sharing25/4/201817/6/2026
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page via a /share/error?message= URI.
ModificadaMedia (5.3)1.0%—Vaultize Enterprise File Sharing25/4/201817/6/2026
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricted, via vectors involving page-by-page access to a document in SWF format.
ModificadaMedia (5.4)0.60%—Vaultize Enterprise File Sharing25/4/201817/6/2026
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field of a file request.
ModificadaCrítica (9.8)17%💥 ExploitCyberark Password Vault12/4/201817/6/2026
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header.
ModificadaMedia (5.3)16%💥 ExploitCyberark Password Vault12/4/201817/6/2026
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.
ModificadaCrítica (9.8)2.4%—Alienvault Open Source Security Information ManagementAlienvault Unified Security Management14/3/201817/6/2026
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
ModificadaCrítica (9.8)16%—Quest Netvault Backup8/2/201817/6/2026
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw exists within JSON RPC Request handling. By setting the checksession parameter to a specific value, it is possible to bypass authentication to critical functions. An…
ModificadaAlta (8.1)4.9%—Quest Netvault Backup8/2/201817/6/2026
This vulnerability allows remote attackers to create a denial-of-service condition on vulnerable installations of Quest NetVault Backup 11.2.0.13. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be easily bypassed. The specific flaw exists within the…
Orbitaley — Vulnerabilidades