Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
697 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.36% | — | Dell Vxrail Hyperconverged Infrastructure | 23/5/2023 | 17/6/2026 | Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the… | |
| Modificada | Media (5.5) | 0.17% | — | Acronis Cyber Infrastructure | 18/5/2023 | 17/6/2026 | Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.3.1-38. | |
| Modificada | Alta (7.5) | 0.39% | — | Acronis Cyber Infrastructure | 28/4/2023 | 17/6/2026 | Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135. | |
| Modificada | Media (6.7) | 0.20% | — | Cisco Evolved Programmable Network ManagerCisco Identity Services EngineCisco Prime Infrastructure | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more… | |
| Modificada | Media (5.4) | 0.57% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information… | |
| Modificada | Media (6.5) | 0.38% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information… | |
| Modificada | Media (6.5) | 0.92% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information… | |
| Modificada | Media (6.5) | 0.92% | — | Cisco Prime Infrastructure | 5/4/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. For more information… | |
| Modificada | Media (6.1) | 0.47% | — | Cisco Prime Infrastructure | 5/4/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of… | |
| Modificada | Alta (7.5) | 0.53% | — | Zoom RoomsZoomZoom Virtual Desktop Infrastructure | 27/3/2023 | 17/6/2026 | Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond… | |
| Modificada | Alta (7.5) | 0.98% | — | Zoom RoomsZoom Virtual Desktop InfrastructureZoom | 16/3/2023 | 17/6/2026 | Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s… | |
| Modificada | Alta (7.8) | 0.19% | — | Cisco Enterprise NFV Infrastructure Software | 10/3/2023 | 17/6/2026 | A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files. An attacker… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due… | |
| Modificada | Alta (8.1) | 0.28% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center Analyzer | 28/2/2023 | 17/6/2026 | Improper Certificate Validation vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component) allows Man in the Middle Attack.This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00;… | |
| Modificada | Alta (7.1) | 0.15% | — | Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+1 | 28/2/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,… | |
| Modificada | Alta (8.8) | 0.36% | — | Cisco Application Policy Infrastructure ControllerCisco Cloud Network Controller | 23/2/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This… | |
| Modificada | Baja (3.3) | 0.18% | — | Intel Wlan Authentication AND Privacy Infrastructure | 11/11/2022 | 17/6/2026 | Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center Analyzer | 1/11/2022 | 17/6/2026 | Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive information. This issue affects Hitachi… | |
| Modificada | Crítica (9.8) | 0.68% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Viewpoint | 1/11/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe components), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe components) allows Server Side Request Forgery.… | |
| Modificada | Media (4.4) | 0.15% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Viewpoint | 1/11/2022 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component), Hitachi Ops Center Viewpoint on Linux (Viewpoint RAID Agent component) allows local users to read and write specific files. This… | |
| Modificada | Crítica (9.6) | 1.3% | — | Zoom MeetingsZoom Rooms FOR Conference RoomsZoom Virtual Desktop Infrastructure | 31/10/2022 | 17/6/2026 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session… | |
| Modificada | Media (5.5) | 0.29% | — | Pulpproject Pulp AnsibleRedhat Ansible Automation PlatformRedhat SatelliteRedhat Update Infrastructure | 25/10/2022 | 17/6/2026 | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only. | |
| Modificada | Alta (7.8) | 0.97% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+15 | 7/10/2022 | 17/6/2026 | A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.97% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+15 | 7/10/2022 | 17/6/2026 | A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code. | |
| Modificada | Alta (7.8) | 1.0% | — | Autodesk AutocadAutodesk Autocad Advance SteelAutodesk Autocad ArchitectureAutodesk Autocad Civil 3D+15 | 7/10/2022 | 17/6/2026 | A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code. |