Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

525 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.86%—Canon OCE Colorwave 500 Firmware19/3/202017/6/2026
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.
ModificadaMedia (6.1)1.4%—Canon OCE Colorwave 500 Firmware19/3/202017/6/2026
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in /home.jsp. The vulnerable parameter is openSI. NOTE: this is fixed in the latest version.
ModificadaMedia (6.1)1.8%—Canon OCE Colorwave 500 Firmware19/3/202017/6/2026
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManager/indexExternalLocation.jsp. The vulnerable parameter is map(template_name). NOTE: this is fixed in the latest version.
ModificadaAlta (7.2)1.9%—Arubanetworks Airwave27/2/202017/6/2026
An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component.
ModificadaAlta (7.2)2.6%—Arubanetworks Airwave27/2/202017/6/2026
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.
ModificadaCrítica (9.8)1.9%—Trustwave Mailmarshal19/2/202017/6/2026
The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.
ModificadaAlta (7.5)2.7%—Arubanetworks AirwaveArubanetworks Aruba InstantArubanetworks Arubaos31/1/202017/6/2026
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672
ModificadaCrítica (9.8)5.1%—Arubanetworks AirwaveArubanetworks Aruba InstantArubanetworks ArubaosSiemens Scalance W1750d Firmware31/1/202017/6/2026
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary…
ModificadaAlta (7.8)0.94%💥 ExploitWaves Maxx Audio16/8/201917/6/2026
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (7.3)0.42%—Waves Maxx Audio3/7/201917/6/2026
WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to DLL side loading. This affects WavesSysSvc64.exe 1.9.29.0.
ModificadaCrítica (9.8)5.2%—Adobe Shockwave Player23/5/201917/6/2026
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)4.1%—Adobe Shockwave Player23/5/201917/6/2026
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)4.1%—Adobe Shockwave Player23/5/201917/6/2026
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)5.2%—Adobe Shockwave Player23/5/201917/6/2026
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)5.2%—Adobe Shockwave Player23/5/201917/6/2026
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)5.2%—Adobe Shockwave Player23/5/201917/6/2026
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.8)5.1%—Adobe Shockwave Player23/5/201917/6/2026
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaCrítica (9.6)28%💥 ExploitWavemaker Wavemarker Studio21/2/201917/6/2026
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
ModificadaCrítica (9.8)1.5%—Net-wave Ming6200 Firmware23/12/201817/6/2026
NETWAVE MNG6200 C4835805jrc12FU121413.cpr devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
ModificadaMedia (6.5)0.46%—Silabs Z-wave S0 FirmwareSilabs Z-wave S2 Firmware9/12/201817/6/2026
An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a DoS attack against the Z-Wave S0 Security version product by continuously sending divided "Nonce Get…
ModificadaMedia (5.3)0.22%—Powermanager KT Mc01507l Z-wave S0 Firmware9/12/201817/6/2026
An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server > Controller (HUB) > Node (products which are controlled by HUB). The prerequisite is that the attacker is on the same network as the target HUB, and can use IP Changer to…
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaMedia (6.1)13%💥 ExploitHP Airwave6/8/201817/6/2026
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative user into clicking a link could obtain…
ModificadaAlta (8.8)9.8%💥 ExploitHP Airwave6/8/201817/6/2026
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because…
Orbitaley — Vulnerabilidades