Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
714 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.71% | — | Opennav Nav2Openrobotics Robot Operating System | 20/2/2024 | 17/6/2026 | Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. | |
| Analizada | Media (6.5) | 0.68% | — | Opennav Nav2Openrobotics Robot Operating System | 20/2/2024 | 17/6/2026 | Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp. | |
| Analizada | Baja (3.3) | 0.29% | — | Opennav Nav2Openrobotics Robot Operating System | 20/2/2024 | 17/6/2026 | Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file. | |
| Modificada | Media (5.4) | 0.29% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the affected user or carry out any actions that this user could perform, or to generally control the victim's browser. | |
| Modificada | Alta (7.8) | 0.64% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.64% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges. | |
| Modificada | Media (6.5) | 0.35% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain unauthorized write access to the files stored on the server filesystem, with elevated privileges. | |
| Modificada | Alta (7.8) | 1.0% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.88% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.88% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the… | |
| Modificada | Alta (7.8) | 0.90% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of… | |
| Modificada | Media (6.5) | 0.42% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information. | |
| Modificada | Alta (7.8) | 0.84% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Media (5.4) | 0.32% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Modificada | Alta (7.8) | 0.84% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands… | |
| Modificada | Alta (7.8) | 0.81% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges. | |
| Modificada | Alta (7.8) | 1.1% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges. | |
| Modificada | Alta (7.8) | 0.95% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 1.1% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges. | |
| Modificada | Media (4.3) | 0.30% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 24/1/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also… | |
| Modificada | Media (4.8) | 0.22% | — | Lesterchan Wp-postratings | 16/1/2024 | 17/6/2026 | The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when… | |
| Modificada | Baja (3.7) | 0.40% | — | Quicoto Thumbs Rating | 19/12/2023 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0. | |
| Modificada | Alta (8.1) | 0.24% | — | Broadcom Fabric Operating System | 6/12/2023 | 17/6/2026 | Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license… | |
| Modificada | Alta (8.1) | 0.40% | — | YET Another Stars Rating Project YET Another Stars Rating | 30/11/2023 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8. | |
| Modificada | Media (5.9) | 0.41% | — | Kamalkhan KK Star Ratings | 27/11/2023 | 17/6/2026 | The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition. |