Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.20%—Vaulteksafe Vt20i Firmware7/12/201717/6/2026
An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session between the Android application and the safe. The website and marketing materials advertise that this communication channel is encrypted with "Highest Level Bluetooth Encryption" and "Data transmissions…
ModificadaAlta (8.8)0.58%—Vaulteksafe Vt20i Firmware7/12/201717/6/2026
An issue was discovered in the software on Vaultek Gun Safe VT20i products, aka BlueSteal. An attacker can remotely unlock any safe in this product line without a valid PIN code. Even though the phone application requires it and there is a field to supply the PIN code in an authorization request, the safe does not…
ModificadaMedia (5.5)0.37%—Netapp Altavault OST Plug-in17/11/201717/6/2026
AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to move to a fixed version and change passwords used by Veritas NetBackup to access the OST shares on the NetApp AltaVault as a precaution.
ModificadaMedia (5.7)1.9%💥 ExploitAlienvault Unified Security Management18/10/201717/6/2026
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send out any report via email to a given address (either in PDF or…
ModificadaAlta (7.8)3.0%—Ansible-vault Project Ansible-vault14/9/201717/6/2026
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.
ModificadaMedia (6.1)0.74%—Openmediavault17/7/201717/6/2026
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
ModificadaAlta (8.1)0.88%—Netapp Altavault3/7/201717/6/2026
NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
ModificadaCrítica (9.8)4.3%💥 ExploitKbvault Mysql Project Kbvault Mysql16/6/201717/6/2026
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any…
ModificadaAlta (7.2)2.7%—Alienvault Open Source Security Information Management23/5/201717/6/2026
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.
ModificadaMedia (6.7)0.51%—Alienvault Open Source Security Information Management23/5/201717/6/2026
The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.
ModificadaCrítica (9.1)0.76%—Vaultive Office 365 Security3/5/201717/6/2026
PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-encrypted"; boundary="abc123abc123"' to 'Content-Type: text/plain' - this results in the encrypted message being…
ModificadaCrítica (9.8)15%💥 ExploitAlienvault OssimAlienvault Unified Security ManagementNfsen22/3/201717/6/2026
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.
ModificadaAlta (8.8)16%💥 ExploitAlienvault OssimAlienvault Unified Security ManagementNfsen22/3/201717/6/2026
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault ID ENG-104862.
ModificadaAlta (8.4)1.7%💥 ExploitAlienvault OssimAlienvault Unified Security ManagementNfsen22/3/201717/6/2026
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-104863.
ModificadaCrítica (9.8)6.4%—Alienvault OssimAlienvault Unified Security Management15/3/201717/6/2026
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP…
ModificadaMedia (6.1)0.64%—Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.
ModificadaCrítica (9.8)57%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
ModificadaMedia (6.1)17%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.
ModificadaCrítica (9.8)6.9%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.
ModificadaMedia (5.4)0.92%—Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management26/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to inject arbitrary web script or HTML via the back parameter to ossim/conf/reload.php.
ModificadaAlta (10)4.0%—Commvault Edge Server4/11/201517/6/2026
The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.
ModificadaMedia (4)2.3%—Tibco Managed File Transfer Internet ServerTibco VaultTibco Managed File Transfer Command CenterTibco Slingshot29/9/201517/6/2026
TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot before 1.9.4, and Vault before 2.0.1 allow remote authenticated users to obtain sensitive information via a crafted HTTP request.
ModificadaMedia (5)8.2%💥 ExploitDell Netvault Backup14/8/201517/6/2026
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
ModificadaAlta (10)1.7%—Gehealthcare Centricity Image Vault Firmware4/8/201516/6/2026
GE Healthcare Centricity Image Vault 3.x has a password of (1) gemnet for the administrator account, (2) webadmin for the webadmin administrator account of the ASACA DVD library, (3) an empty value for the gemsservice account of the Ultrasound Database, and possibly (4) gemnet2002 for the gemnet2002 account of the…
ModificadaAlta (10)6.0%—Dell Netvault Backup29/5/201517/6/2026
Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow.
Orbitaley — Vulnerabilidades