Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.86% | — | Canon OCE Colorwave 500 Firmware | 19/3/2020 | 17/6/2026 | The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version. | |
| Modificada | Media (6.1) | 1.4% | — | Canon OCE Colorwave 500 Firmware | 19/3/2020 | 17/6/2026 | The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in /home.jsp. The vulnerable parameter is openSI. NOTE: this is fixed in the latest version. | |
| Modificada | Media (6.1) | 1.8% | — | Canon OCE Colorwave 500 Firmware | 19/3/2020 | 17/6/2026 | The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManager/indexExternalLocation.jsp. The vulnerable parameter is map(template_name). NOTE: this is fixed in the latest version. | |
| Modificada | Alta (7.2) | 1.9% | — | Arubanetworks Airwave | 27/2/2020 | 17/6/2026 | An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain code execution on the AMP platform. This is possible due to the ability to overwrite a file on disk which is subsequently deserialized by the Java application component. | |
| Modificada | Alta (7.2) | 2.6% | — | Arubanetworks Airwave | 27/2/2020 | 17/6/2026 | There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host. | |
| Modificada | Crítica (9.8) | 1.9% | — | Trustwave Mailmarshal | 19/2/2020 | 17/6/2026 | The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection. | |
| Modificada | Alta (7.5) | 2.7% | — | Arubanetworks AirwaveArubanetworks Aruba InstantArubanetworks Arubaos | 31/1/2020 | 17/6/2026 | A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672 | |
| Modificada | Crítica (9.8) | 5.1% | — | Arubanetworks AirwaveArubanetworks Aruba InstantArubanetworks ArubaosSiemens Scalance W1750d Firmware | 31/1/2020 | 17/6/2026 | Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary… | |
| Modificada | Alta (7.8) | 0.94% | 💥 Exploit | Waves Maxx Audio | 16/8/2019 | 17/6/2026 | Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (7.3) | 0.42% | — | Waves Maxx Audio | 3/7/2019 | 17/6/2026 | WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to DLL side loading. This affects WavesSysSvc64.exe 1.9.29.0. | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 4.1% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 4.1% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.2% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 5.1% | — | Adobe Shockwave Player | 23/5/2019 | 17/6/2026 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Crítica (9.6) | 28% | 💥 Exploit | Wavemaker Wavemarker Studio | 21/2/2019 | 17/6/2026 | com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF. | |
| Modificada | Crítica (9.8) | 1.5% | — | Net-wave Ming6200 Firmware | 23/12/2018 | 17/6/2026 | NETWAVE MNG6200 C4835805jrc12FU121413.cpr devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. | |
| Modificada | Media (6.5) | 0.46% | — | Silabs Z-wave S0 FirmwareSilabs Z-wave S2 Firmware | 9/12/2018 | 17/6/2026 | An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a DoS attack against the Z-Wave S0 Security version product by continuously sending divided "Nonce Get… | |
| Modificada | Media (5.3) | 0.22% | — | Powermanager KT Mc01507l Z-wave S0 Firmware | 9/12/2018 | 17/6/2026 | An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server > Controller (HUB) > Node (products which are controlled by HUB). The prerequisite is that the attacker is on the same network as the target HUB, and can use IP Changer to… | |
| Modificada | Alta (7.5) | 74% | — | Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+34 | 6/8/2018 | 17/6/2026 | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | |
| Modificada | Media (6.1) | 13% | 💥 Exploit | HP Airwave | 6/8/2018 | 17/6/2026 | Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative user into clicking a link could obtain… | |
| Modificada | Alta (8.8) | 9.8% | 💥 Exploit | HP Airwave | 6/8/2018 | 17/6/2026 | Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because… |