Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

368 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.4)19%—HP Network Virtualization26/7/201417/6/2026
Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to create files, and consequently execute arbitrary code, via crafted input, aka ZDI-CAN-2024.
ModificadaAlta (8.5)9.9%—HP Network Virtualization26/7/201417/6/2026
Directory traversal vulnerability in the storedNtxFile function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to read arbitrary files via crafted input, aka ZDI-CAN-2023.
ModificadaMedia (4.3)2.1%—Oracle VirtualizationOracle Virtualization Secure Global Desktop17/7/201417/6/2026
Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect integrity via unknown vectors related to Workspace Web Application, a different vulnerability than CVE-2014-2463.
ModificadaMedia (4)1.5%—Redhat Enterprise Virtualization11/7/201417/6/2026
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.
ModificadaAlta (10)78%💥 ExploitHP Service Virtualization18/6/201417/6/2026
Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.
ModificadaMedia (6)0.27%—IBM System Storage Virtualization Engine Ts7700 FirmwareIBM System Storage Virtualization Engine Ts77008/6/201417/6/2026
Unspecified vulnerability on the IBM System Storage Virtualization Engine TS7700 allows local users to gain privileges by leveraging the TSSC service-user role to enter a crafted SSH command.
ModificadaMedia (5)3.8%—GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+105/6/201417/6/2026
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
ModificadaAlta (7.5)3.8%—GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+115/6/201417/6/2026
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
ModificadaMedia (5)6.8%—GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+115/6/201417/6/2026
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
ModificadaMedia (4.3)1.5%—Oracle Virtualization16/4/201417/6/2026
Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect integrity via unknown vectors related to Workspace Web Application, a different vulnerability than CVE-2014-4232.
ModificadaMedia (6.4)1.8%—Oracle Virtualization16/4/201417/6/2026
Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Workspace Web Application.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitOpensslFilezilla-project Filezilla ServerSiemens Application Processing Engine FirmwareSiemens CP 1543-1 Firmware+247/4/201417/6/2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to…
ModificadaMedia (6.8)3.2%—GNU GlibcRedhat Enterprise VirtualizationCanonical Ubuntu LinuxRedhat Enterprise Linux10/2/201416/6/2026
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and…
ModificadaMedia (5)2.1%—GNU GlibcRedhat Enterprise VirtualizationCanonical Ubuntu LinuxRedhat Enterprise Linux10/2/201416/6/2026
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and…
ModificadaMedia (5)2.2%—GNU GlibcRedhat Enterprise VirtualizationCanonical Ubuntu LinuxRedhat Enterprise Linux10/2/201416/6/2026
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (stack corruption and crash)…
ModificadaMedia (4.3)0.97%—Redhat Enterprise Virtualization Manager24/1/201417/6/2026
The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.
ModificadaAlta (7.2)0.41%—Redhat Enterprise Virtualization21/1/201416/6/2026
Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder.
ModificadaAlta (7.2)0.41%—Redhat Enterprise Virtualization21/1/201416/6/2026
Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified folder.
ModificadaMedia (5.1)1.5%—Oracle Virtualization Secure Global Desktop15/1/201417/6/2026
Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization SGD before 4.63 with December 2013 PSU, 4.71, 5.0 with December 2013 PSU, and 5.10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration Console…
ModificadaAlta (7.5)16%—Redhat Cloudforms Management EngineRedhat Manageiq Enterprise Virtualization Manager11/1/201416/6/2026
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.
ModificadaAlta (7.4)0.54%—Redhat Enterprise Virtualization Hypervisor27/12/201316/6/2026
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
ModificadaMedia (5)2.7%—Spice Project SpiceRedhat Enterprise VirtualizationRedhat Enterprise Linux2/11/201316/6/2026
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
ModificadaMedia (5)1.3%—Oracle Virtualization16/10/201316/6/2026
Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5 allows remote attackers to affect availability via unknown vectors related to ttaauxserv.
ModificadaAlta (7.2)0.43%—QemuOpensuseRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+34/10/201316/6/2026
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
ModificadaMedia (4.3)1.4%—Redhat Enterprise Virtualization16/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M), as used in Red Hat Enterprise Virtualization 3 and 3.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Orbitaley — Vulnerabilidades