Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.63% | — | Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance | 28/7/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write files to a NetBackup Primary server. | |
| Modificada | Crítica (9.8) | 0.95% | — | Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance | 28/7/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unauthenticated access could remotely execute arbitrary commands on a NetBackup Primary server. | |
| Modificada | Alta (7.8) | 0.20% | — | Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance | 28/7/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unprivileged local access to a Windows NetBackup Primary server could potentially escalate their privileges. | |
| Modificada | Media (6.5) | 0.74% | — | Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance | 28/7/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a denial of service attack against a NetBackup Primary server. | |
| Modificada | Media (6.4) | 0.66% | — | Oracle Flexcube Universal Banking | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.7) | 0.66% | — | Oracle Flexcube Universal Banking | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.4) | 0.66% | — | Oracle Flexcube Universal Banking | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.4) | 0.61% | — | Oracle Flexcube Universal Banking | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Alta (7.1) | 0.83% | — | Oracle Flexcube Universal Banking | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Media (6.7) | 0.70% | — | Oracle Flexcube Universal Banking | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Alta (7.8) | 0.35% | — | Sick Flexi Soft Designer | 19/7/2022 | 17/6/2026 | A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the… | |
| Modificada | Alta (7.8) | 1.1% | 💥 Exploit | Zyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+21 | 19/7/2022 | 17/6/2026 | A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions… | |
| Modificada | Media (6.5) | 1.4% | — | Zyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+21 | 19/7/2022 | 17/6/2026 | A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX… | |
| Modificada | Media (4.8) | 0.43% | — | HPE Flexnetwork 5130 EI FirmwareHPE Flexfabric 5945 Firmware | 8/7/2022 | 17/6/2026 | A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE FlexNetwork 5130EL_7.10.R3507P02 and HPE… | |
| Modificada | Alta (7.8) | 4.8% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+61 | 24/5/2022 | 17/6/2026 | A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00… | |
| Modificada | Alta (7.8) | 6.2% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+61 | 24/5/2022 | 17/6/2026 | Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions… | |
| Modificada | Media (6.5) | 0.71% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+28 | 24/5/2022 | 17/6/2026 | A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through… | |
| Modificada | Media (6.1) | 9.4% | — | Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+28 | 24/5/2022 | 17/6/2026 | A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+12 | 12/5/2022 | 17/6/2026 | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W)… | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo C340-14iml FirmwareLenovo C340-15iml FirmwareLenovo D330-10igm FirmwareLenovo Duet 3-10igl5 Firmware+58 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.1) | 0.56% | — | NI FlexloggerNI G WEB Development SoftwareNI LabviewNI Static Test Software Suite+1 | 21/4/2022 | 17/6/2026 | There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development… | |
| Modificada | Media (5.9) | 0.63% | — | Oracle Flexcube Universal Banking | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.7) | 0.24% | — | HPE Superdome Flex Server FirmwareHPE Superdome Flex 280 Server Firmware | 12/4/2022 | 17/6/2026 | A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnerability could be locally exploited to allow an user with Administrator access to escalate their privilege. The vulnerability is resolved in the latest firmware update. HPE Superdome Flex Server… | |
| Modificada | Crítica (9.8) | 5.2% | — | Rockwellautomation Compactlogix 1768-l43 FirmwareRockwellautomation Compactlogix 1768-l45 FirmwareRockwellautomation Compactlogix 1769-l31 FirmwareRockwellautomation Compactlogix 1769-l32c Firmware+20 | 11/4/2022 | 17/6/2026 | An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the… | |
| Modificada | Alta (7.5) | 1.3% | 💥 PoC | Flexwatch Fw3170-ps-e Firmware | 5/4/2022 | 17/6/2026 | Seyeon Tech Co., Ltd FlexWATCH FW3170-PS-E Network Video System 4.23-3000_GY allows attackers to access sensitive information. |