Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.5% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by sending specially crafted UDP requests. | |
| Modificada | Media (6.7) | 0.17% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with access to the system files may use the… | |
| Modificada | Media (6.7) | 0.26% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker with access to the log files may use the… | |
| Modificada | Media (4.8) | 1.1% | 💥 Exploit | Invisioncommunity Community | 30/12/2020 | 9/7/2026 | Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload. | |
| Modificada | Alta (8.6) | 1.4% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PRO | 11/12/2020 | 17/6/2026 | A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the software or unexpected code execution when opening a malicious file in EcoStruxure™ Control Expert software. | |
| Modificada | Alta (8.8) | 1.5% | — | Silver-peak Unity Orchestrator | 5/11/2020 | 17/6/2026 | In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing. | |
| Modificada | Alta (8.8) | 28% | — | Silver-peak Unity Orchestrator | 5/11/2020 | 17/6/2026 | In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API. | |
| Modificada | Crítica (9.8) | 6.0% | — | Silver-peak Unity Orchestrator | 5/11/2020 | 17/6/2026 | Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to Orchestrator by introducing an HTTP HOST header set to 127.0.0.1 or localhost. Orchestrator instances that are hosted by customers… | |
| Modificada | Alta (7.5) | 1.4% | — | Ansible Collections Project Community.crypto | 29/10/2020 | 17/6/2026 | A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality | |
| Modificada | Media (6.5) | 1.8% | — | Cisco Unity Connection | 23/9/2020 | 17/6/2026 | A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web… | |
| Modificada | Media (6.1) | 0.80% | — | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 2/7/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a… | |
| Modificada | Crítica (9.8) | 1.4% | — | Schneider-electric OS LoaderSchneider-electric Unity Loader | 16/6/2020 | 17/6/2026 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fixed credentials is considered a vulnerability, which could cause unauthorized access to the file transfer service… | |
| Modificada | Media (4.6) | 0.37% | — | Ubports Unity8 | 7/5/2020 | 17/6/2026 | Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. This allows an attacker to enable the MTP service by opening the emergency dialer. Fixed in 8.11+16.04.20160111.1-0ubuntu1 and 8.11+15.04.20160122-0ubuntu1. | |
| Modificada | Media (4.9) | 0.34% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal. | |
| Modificada | Media (4.9) | 0.34% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator. | |
| Modificada | Media (4.9) | 0.72% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell… | |
| Modificada | Media (5) | 0.95% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 15/4/2020 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Self-Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Modificada | Crítica (9.8) | 1.6% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PROSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon M580 Firmware | 23/3/2020 | 17/6/2026 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior… | |
| Modificada | Media (6.1) | 3.5% | — | Invisioncommunity Invision Power BoardMicrosoft Internet Explorer | 13/3/2020 | 16/6/2026 | Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment. | |
| Modificada | Media (5.4) | 0.55% | — | Telligent Community | 13/2/2020 | 16/6/2026 | XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter. | |
| Modificada | Crítica (9.8) | 1.8% | — | Invisioncommunity Invision Power Board | 12/2/2020 | 16/6/2026 | Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution. | |
| Modificada | Alta (7.5) | 1.4% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity XT Operating EnvironmentDell EMC Unityvsa Operating Environment | 6/2/2020 | 17/6/2026 | Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit this vulnerability and cause a Denial of… | |
| Modificada | Media (4.8) | 0.62% | — | Cisco Unity Connection | 26/1/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 7.4% | 💥 Exploit | Invisioncommunity Invision Power Board | 9/1/2020 | 16/6/2026 | Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file. | |
| Modificada | Alta (7.3) | 0.95% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PROSchneider-electric Modicon M580 Bmep584040 FirmwareSchneider-electric Modicon M580 Bmeh584040 Firmware+19 | 6/1/2020 | 17/6/2026 | Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control… |