Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.39%—Hcltechsw Bigfix Bare OSD Metal Server Webui16/1/202417/6/2026
Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.
ModificadaCrítica (9.8)0.41%—Hcltechsw Bigfix Bare OSD Metal Server Webui16/1/202417/6/2026
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.
ModificadaMedia (5.3)0.33%—Hcltechsw Bigfix Bare OSD Metal Server Webui16/1/202417/6/2026
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.
ModificadaAlta (7.5)0.57%—Zanllp Stable Diffusion Webui Infinite Image Browsing22/10/202317/6/2026
The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion web UI), if Gradio authentication is enabled without secret key configuration, allows remote attackers to read any local file via /file?path= in the URL, as demonstrated…
ModificadaAlta (7.5)3.4%💥 ExploitZiahamza Webui-aria222/8/202317/6/2026
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
ModificadaMedia (6.5)0.16%—Hcltech Bigfix Webui18/7/202317/6/2026
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network).
ModificadaAlta (7.5)0.30%—Hcltech Bigfix Webui18/7/202317/6/2026
The BigFix WebUI uses weak cipher suites.
ModificadaMedia (6.1)0.36%—Hcltech Bigfix Webui18/7/202317/6/2026
URL redirection in Login page in HCL BigFix WebUI allows malicious user to redirect the client browser to an external site via redirect URL response header.
ModificadaAlta (8.8)0.45%—Hcltech Bigfix Webui18/7/202317/6/2026
Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query.
ModificadaMedia (6.5)0.42%—Hcltech Bigfix Webui Insights23/6/202317/6/2026
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
ModificadaMedia (5.8)0.39%—Hcltech Bigfix Webui21/12/202217/6/2026
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
ModificadaMedia (6.5)0.55%—Hcltech Bigfix Webui6/5/202217/6/2026
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
ModificadaMedia (5.4)0.52%—Hcltech Bigfix Webui17/7/202017/6/2026
HCL BigFix WebUI is vulnerable to stored cross-site scripting (XSS) within the Apps->Software module. An attacker can use XSS to send a malicious script to an unsuspecting user. This affects all versions prior to latest releases as specified in…
ModificadaCrítica (9.8)2.1%—IBM Bigfix Webui Profile ManagementIBM Bigfix Webui Software Distribution15/4/201917/6/2026
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 155886.
ModificadaMedia (5)0.84%—Huawei WebuiHuawei E355s Mobile Wifi Firmware21/5/201517/6/2026
Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configuration information by sniffing the network or sending unspecified commands.
ModificadaMedia (6.8)1.1%💥 ExploitHuawei WebuiHuawei E303 Modem FirmwareHuawei E303 Modem2/6/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML…
ModificadaMedia (6.8)2.7%💥 ExploitUtorrent Webui3/4/200916/6/2026
Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests that force the download of arbitrary torrent files via the add-url action and (2) hijack the authentication of administrators for requests…
Orbitaley — Vulnerabilidades