Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.13% | — | IBM MQ OperatorIBM Supplied MQ Advanced Container Images | 24/7/2025 | 17/6/2026 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory before release. | |
| Analizada | Alta (7.8) | 0.21% | — | Openrobotics Robot Operating System | 17/7/2025 | 17/6/2026 | A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function to process unsanitized, user-supplied input in the 'rosbag filter' command. This flaw enables… | |
| Analizada | Alta (7.8) | 0.21% | — | Openrobotics Robot Operating System | 17/7/2025 | 17/6/2026 | A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'echo' verb, which allows a user to introspect a ROS topic and accepts a user-provided Python expression via the… | |
| Analizada | Alta (7.8) | 0.21% | — | Openrobotics Robot Operating System | 17/7/2025 | 17/6/2026 | A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the… | |
| Analizada | Alta (7.8) | 0.19% | — | Openrobotics Robot Operating System | 17/7/2025 | 17/6/2026 | A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() method to process user-supplied, unsanitized parameter values within the substitution args… | |
| Analizada | Alta (7.8) | 0.19% | — | Openrobotics Robot Operating System | 17/7/2025 | 17/6/2026 | A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability stems from the use of the eval() function to process unsanitized, user-supplied parameter values via special converters for angle… | |
| Analizada | Media (6.9) | 0.34% | — | Openai Operator | 10/7/2025 | 17/6/2026 | Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive fullscreen interface with overlaid fake browser controls and a… | |
| Analizada | Media (6.8) | 0.33% | — | Broadcom Fabric Operating System | 8/7/2025 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service (DoS). The vulnerability is encountered when supportsave is invoked remotely, using ssh command or SANnav inline ssh, and the… | |
| Analizada | Media (4.8) | 0.21% | — | Broadcom Fabric Operating System | 19/6/2025 | 17/6/2026 | A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privilege is required on the switch in order to exploit | |
| Analizada | Crítica (9.8) | 0.36% | 💥 PoC | IBM MQ OperatorIBM Supplied MQ Advanced Container Images | 15/6/2025 | 17/6/2026 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than the intended key which could disclose sensitive information or… | |
| Modificada | Alta (7.5) | 1.4% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+16 | 12/6/2025 | 18/9/2026 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input. | |
| Aplazada | Media (5.5) | 0.17% | — | Apache Activemq ArtemisAIActivemq Artemis OperatorAI | 26/5/2025 | 17/6/2026 | A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies. | |
| Analizada | Media (5.5) | 0.13% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 9/5/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic… | |
| Aplazada | Crítica (9.4) | 0.35% | — | Opentext Operations Bridge ManagerAI | 7/5/2025 | 17/6/2026 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4. | |
| Aplazada | Media (6.7) | 0.18% | — | Opentext Operations Bridge ManagerAI | 7/5/2025 | 17/6/2026 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allow authenticated users to change their password without providing their old password. This issue affects Operations Bridge Manager: 24.2, 24.4. | |
| Analizada | Media (6.5) | 0.39% | — | IBM MQ OperatorIBM Supplied MQ Advanced Container Images | 1/5/2025 | 17/6/2026 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it. | |
| Analizada | Media (6.5) | 0.28% | — | IBM MQ OperatorIBM Supplied MQ Advanced Container Images | 1/5/2025 | 17/6/2026 | IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to a privileged user. | |
| Analizada | Media (6.1) | 0.26% | — | IBM Operational Decision Manager | 29/4/2025 | 17/6/2026 | IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Analizada | Alta (8.6) | 0.69% | ⚠ Explotación activa | Broadcom Fabric Operating System | 24/4/2025 | 17/6/2026 | Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6. | |
| Aplazada | Media (5.5) | 0.19% | — | Cray Operating SystemAI | 22/4/2025 | 17/6/2026 | A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack. | |
| Aplazada | Media (6.9) | 0.62% | — | Minio OperatorAI | 22/4/2025 | 17/6/2026 | MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may unintentionally trust it. This issue has been… | |
| Aplazada | Alta (8.7) | 0.33% | — | Opentext Operations Bridge ManagerAIOpentext Operations Bridge SuiteAIOpentext UcmdbAI | 17/4/2025 | 17/6/2026 | Incorrect Use of Privileged APIs vulnerability in OpenText™ Operations Bridge Manager, OpenText™ Operations Bridge Suite (Containerized), OpenText™ UCMDB ( Classic and Containerized) allows Privilege Escalation. The vulnerability could allow authenticated attackers to elevate user privileges. This issue affects… | |
| Aplazada | Media (5) | 0.17% | — | Canonical Charmed Mysql K8S OperatorAI | 9/4/2025 | 17/6/2026 | Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a SQL DDL or python based mysql-shell scripts can leak database users credentials. The method mysql-operator calls mysql-shell application rely on writing to a temporary script file containing… | |
| Analizada | Alta (7.8) | 0.88% | — | Microsoft System Center Data Protection ManagerMicrosoft System Center Operations ManagerMicrosoft System Center OrchestratorMicrosoft System Center Service Manager+1 | 8/4/2025 | 17/6/2026 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.53% | — | Dell Powerprotect Data DomainDell Data Domain Operating SystemDell Powerprotect Dm5500 Firmware | 3/4/2025 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary commands with root privileges. |