Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.39% | — | Hcltechsw Bigfix Bare OSD Metal Server Webui | 16/1/2024 | 17/6/2026 | Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser. | |
| Modificada | Crítica (9.8) | 0.41% | — | Hcltechsw Bigfix Bare OSD Metal Server Webui | 16/1/2024 | 17/6/2026 | HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser. | |
| Modificada | Media (5.3) | 0.33% | — | Hcltechsw Bigfix Bare OSD Metal Server Webui | 16/1/2024 | 17/6/2026 | HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack. | |
| Modificada | Alta (7.5) | 0.57% | — | Zanllp Stable Diffusion Webui Infinite Image Browsing | 22/10/2023 | 17/6/2026 | The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion web UI), if Gradio authentication is enabled without secret key configuration, allows remote attackers to read any local file via /file?path= in the URL, as demonstrated… | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Ziahamza Webui-aria2 | 22/8/2023 | 17/6/2026 | webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability. | |
| Modificada | Media (6.5) | 0.16% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). | |
| Modificada | Alta (7.5) | 0.30% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | The BigFix WebUI uses weak cipher suites. | |
| Modificada | Media (6.1) | 0.36% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header. | |
| Modificada | Alta (8.8) | 0.45% | — | Hcltech Bigfix Webui | 18/7/2023 | 17/6/2026 | Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query. | |
| Modificada | Media (6.5) | 0.42% | — | Hcltech Bigfix Webui Insights | 23/6/2023 | 17/6/2026 | A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page. | |
| Modificada | Media (5.8) | 0.39% | — | Hcltech Bigfix Webui | 21/12/2022 | 17/6/2026 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site. | |
| Modificada | Media (6.5) | 0.55% | — | Hcltech Bigfix Webui | 6/5/2022 | 17/6/2026 | Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) | |
| Modificada | Media (5.4) | 0.52% | — | Hcltech Bigfix Webui | 17/7/2020 | 17/6/2026 | HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in… | |
| Modificada | Crítica (9.8) | 2.1% | — | IBM Bigfix Webui Profile ManagementIBM Bigfix Webui Software Distribution | 15/4/2019 | 17/6/2026 | IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 155886. | |
| Modificada | Media (5) | 0.84% | — | Huawei WebuiHuawei E355s Mobile Wifi Firmware | 21/5/2015 | 17/6/2026 | Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configuration information by sniffing the network or sending unspecified commands. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Huawei WebuiHuawei E303 Modem FirmwareHuawei E303 Modem | 2/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML… | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Utorrent Webui | 3/4/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests that force the download of arbitrary torrent files via the add-url action and (2) hijack the authentication of administrators for requests… |