Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Hashicorp Vault | 10/6/2020 | 17/6/2026 | HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in… | |
| Modificada | Crítica (9.1) | 1.1% | — | Hashicorp Vault | 23/3/2020 | 17/6/2026 | HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4. | |
| Modificada | Media (5.3) | 0.76% | — | Hashicorp Vault | 23/3/2020 | 17/6/2026 | HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4. | |
| Modificada | Alta (7.5) | 1.7% | — | Alienvault Open Source Security Information Management | 27/1/2020 | 16/6/2026 | OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability | |
| Modificada | Alta (7.5) | 1.4% | — | Hashicorp Vault | 23/1/2020 | 17/6/2026 | HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2. | |
| Modificada | Alta (7.8) | 0.49% | — | Linux KernelRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Power Little Endian EUSRedhat Enterprise Linux+14 | 25/11/2019 | 17/6/2026 | A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver. | |
| Modificada | Alta (7.5) | 0.89% | — | Jenkins Sourcegear Vault | 1/10/2019 | 17/6/2026 | Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure. | |
| Modificada | Baja (2.4) | 0.42% | — | Real-sec BC Vault Firmware | 12/8/2019 | 17/6/2026 | On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this… | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Cyberark Enterprise Password Vault | 8/5/2019 | 17/6/2026 | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system. | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Crítica (9.8) | 1.6% | — | Photorange Photo Vault Project Photorange Photo Vault | 23/12/2018 | 17/6/2026 | PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on. | |
| Modificada | Alta (8.1) | 0.93% | — | Hashicorp Vault | 5/12/2018 | 17/6/2026 | HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported. | |
| Modificada | Media (5.4) | 0.60% | — | Vaultize Enterprise File Sharing | 25/4/2018 | 17/6/2026 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a different user, who can modify the HTML in that mail before sending it. | |
| Modificada | Media (5.4) | 0.63% | — | Vaultize Enterprise File Sharing | 25/4/2018 | 17/6/2026 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value. | |
| Modificada | Media (5.3) | 1.0% | — | Vaultize Enterprise File Sharing | 25/4/2018 | 17/6/2026 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie. | |
| Modificada | Media (5.3) | 1.0% | — | Vaultize Enterprise File Sharing | 25/4/2018 | 17/6/2026 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature. | |
| Modificada | Media (5.4) | 0.60% | — | Vaultize Enterprise File Sharing | 25/4/2018 | 17/6/2026 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download pop-up via a crafted file or folder name. | |
| Modificada | Media (6.1) | 0.78% | — | Vaultize Enterprise File Sharing | 25/4/2018 | 17/6/2026 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page via a /share/error?message= URI. | |
| Modificada | Media (5.3) | 1.0% | — | Vaultize Enterprise File Sharing | 25/4/2018 | 17/6/2026 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricted, via vectors involving page-by-page access to a document in SWF format. | |
| Modificada | Media (5.4) | 0.60% | — | Vaultize Enterprise File Sharing | 25/4/2018 | 17/6/2026 | An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field of a file request. | |
| Modificada | Crítica (9.8) | 17% | 💥 Exploit | Cyberark Password Vault | 12/4/2018 | 17/6/2026 | The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header. | |
| Modificada | Media (5.3) | 16% | 💥 Exploit | Cyberark Password Vault | 12/4/2018 | 17/6/2026 | CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. | |
| Modificada | Crítica (9.8) | 2.4% | — | Alienvault Open Source Security Information ManagementAlienvault Unified Security Management | 14/3/2018 | 17/6/2026 | A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1. | |
| Modificada | Crítica (9.8) | 16% | — | Quest Netvault Backup | 8/2/2018 | 17/6/2026 | This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw exists within JSON RPC Request handling. By setting the checksession parameter to a specific value, it is possible to bypass authentication to critical functions. An… | |
| Modificada | Alta (8.1) | 4.9% | — | Quest Netvault Backup | 8/2/2018 | 17/6/2026 | This vulnerability allows remote attackers to create a denial-of-service condition on vulnerable installations of Quest NetVault Backup 11.2.0.13. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be easily bypassed. The specific flaw exists within the… |