Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.39% | — | Tempo OperatorAIJaeger UIAI | 2/4/2025 | 8/9/2026 | A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user… | |
| Aplazada | Media (4.3) | 0.37% | — | Tempo OperatorAI | 2/4/2025 | 8/9/2026 | A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and… | |
| Analizada | Crítica (9.8) | 0.40% | — | Openrobotics Robot Operating System | 2/4/2025 | 17/6/2026 | A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set'… | |
| Aplazada | Media (6.5) | 0.36% | — | Wpoperations Wpop-elementor-addonsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpoperations WPoperation Elementor Addons wpop-elementor-addons allows Stored XSS.This issue affects WPoperation Elementor Addons: from n/a through <= 1.1.9. | |
| Aplazada | Alta (7.8) | 0.15% | — | Vmware Aria OperationsAI | 1/4/2025 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations. | |
| Aplazada | Alta (7) | 0.17% | — | Valmet DNA OperateAI | 1/4/2025 | 17/6/2026 | Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.53% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges. | |
| Analizada | Alta (8.8) | 1.4% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be… | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.59% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.59% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.54% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Crítica (9.8) | 1.5% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Crítica (9.1) | 1.1% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical… | |
| Analizada | Alta (7.3) | 1.3% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Crítica (9.8) | 2.0% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may… | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.57% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root… | |
| Analizada | Alta (7.8) | 0.58% | — | Dell Unity Operating Environment | 28/3/2025 | 17/6/2026 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root… | |
| Aplazada | Alta (7.1) | 0.39% | — | Narnoo OperatorAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Narnoo Narnoo Operator narnoo-shortcodes allows Reflected XSS.This issue affects Narnoo Operator: from n/a through <= 2.0.0. | |
| Aplazada | Media (6.5) | 0.18% | — | Metal3 Baremetal OperatorAI | 17/3/2025 | 17/6/2026 | The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator enables users to load Secret from arbitrary namespaces upon deployment of the namespace scoped Custom Resource `BMCEventSubscription`. Prior to versions 0.8.1 and 0.9.1, an adversary Kubernetes account… | |
| Analizada | Media (6.5) | 0.48% | — | IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator | 12/3/2025 | 17/6/2026 | IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a denial of service in the App Connect flow due to improper validation of… | |
| Aplazada | Media (5.3) | 0.31% | — | Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management AND Operations SystemAI | 1/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this issue is some unknown functionality of the file /wuser/anyUserBoundHouse.php. The manipulation of the argument huid leads to… |