Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1488 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.36%—Rapid7 Insightvm24/3/202317/6/2026
Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user account's current session is still valid after…
ModificadaAlta (8.8)1.2%—Rapid7 InsightappsecRapid7 Insightcloudsec21/3/202317/6/2026
An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.
ModificadaAlta (8.1)0.78%—Rapid7 InsightappsecRapid7 Insightcloudsec21/3/202317/6/2026
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.
ModificadaAlta (8.8)1.1%—Rapid7 InsightappsecRapid7 Insightcloudsec21/3/202317/6/2026
An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are normally expected to be private methods. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version…
ModificadaMedia (6.1)0.33%—Rapid7 Insightvm20/3/202317/6/2026
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application. This issue was resolved in the February, 2023…
ModificadaMedia (4.5)4.0%💥 ExploitMicrosoft Azure Hdinsight14/3/202317/6/2026
Azure Apache Ambari Spoofing Vulnerability
ModificadaMedia (5.4)0.59%—Monsterinsights6/2/202317/6/2026
The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.3)24%💥 ExploitVmware Vrealize LOG Insight26/1/202317/6/2026
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.
ModificadaAlta (7.5)1.5%—Vmware Vrealize LOG Insight26/1/202317/6/2026
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
ModificadaCrítica (9.8)87%💥 ExploitVmware Vrealize LOG Insight26/1/202317/6/2026
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
ModificadaCrítica (9.8)81%💥 ExploitVmware Vrealize LOG Insight26/1/202317/6/2026
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
ModificadaMedia (6.1)1.3%💥 PoCMonsterinsights16/1/202317/6/2026
The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.
ModificadaAlta (7.7)0.38%—Rapid7 Insightvm12/1/202317/6/2026
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.
ModificadaAlta (7.5)17%—Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+323/12/202217/6/2026
A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS mechanism could be bypassed if the host name in…
ModificadaMedia (6.5)0.41%—Hcltechsw Bigfix Insights FOR Vulnerability Remediation21/12/202217/6/2026
Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information disclosure. This requires privileged access.
ModificadaMedia (5.3)0.22%—Hcltechsw Bigfix Insights FOR Vulnerability Remediation21/12/202217/6/2026
Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information disclosure. This requires privileged network access.
ModificadaAlta (8.6)0.54%—Netapp Oncommand Insight20/12/202217/6/2026
OnCommand Insight versions 7.3.1 through 7.3.14 are susceptible to an authentication bypass vulnerability in the Data Warehouse component.
ModificadaAlta (7.5)1.9%—Vmware Vrealize LOG Insight14/12/202217/6/2026
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
ModificadaCrítica (9.8)1.7%—Vmware Vrealize Network Insight14/12/202217/6/2026
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.
ModificadaMedia (6.5)0.32%—Rapid7 InsightvmRapid7 Nexpose8/12/202217/6/2026
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update,…
ModificadaMedia (6.5)1.3%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.5)1.3%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)1.3%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaBaja (3.7)1.6%—Oracle GraalvmOracle JDKOracle JREFedoraproject Fedora+1118/10/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows…
ModificadaMedia (4.9)1.1%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow Automation18/10/202217/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
Orbitaley — Vulnerabilidades