Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.99% | — | IBM Urbancode Deploy | 6/11/2020 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 181857. | |
| Modificada | Media (6.5) | 0.87% | — | IBM Urbancode Deploy | 6/11/2020 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow an authenticated user to bypass security. A user with access to a snapshot could apply unauthorized additional statuses via direct rest calls. IBM X-Force ID: 181856. | |
| Analizada | Crítica (9.6) | 64% | ⚠ Explotación activa💥 PoC | Google ChromeFreetypeDebian LinuxFedoraproject Fedora+2 | 3/11/2020 | 17/6/2026 | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.1) | 1.1% | — | Octopus Deploy | 26/10/2020 | 17/6/2026 | In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header. | |
| Modificada | Alta (7.5) | 1.3% | — | Octopus Deploy | 22/10/2020 | 17/6/2026 | An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one. | |
| Modificada | Alta (7.5) | 1.5% | — | Octopus Deploy | 12/10/2020 | 17/6/2026 | In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs. | |
| Modificada | Alta (7.5) | 1.8% | — | Octopus Deploy | 9/9/2020 | 17/6/2026 | In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password is exposed in cleartext in the verbose… | |
| Modificada | Alta (7.7) | 1.2% | — | Cloudfoundry Cf-deploymentCloudfoundry Gorouter | 3/9/2020 | 17/6/2026 | Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF cluster by pushing an app that returns specially crafted HTTP responses that crash the Gorouters. | |
| Modificada | Media (4.3) | 0.57% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 3/9/2020 | 17/6/2026 | Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none). | |
| Modificada | Alta (8.8) | 0.99% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 21/8/2020 | 17/6/2026 | Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developers maliciously or accidentally claiming certain sensitive routes, potentially resulting in the… | |
| Modificada | Media (6.5) | 1.2% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 21/8/2020 | 17/6/2026 | Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be… | |
| Modificada | Alta (8.2) | 2.0% | — | IBM Urbancode Deploy | 5/8/2020 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181848. | |
| Modificada | Media (5.9) | 2.9% | — | Golang GOCloudfoundry Cf-deploymentCloudfoundry Routing-releaseDebian Linux+2 | 17/7/2020 | 17/6/2026 | Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time. | |
| Modificada | Media (5.4) | 0.69% | — | Jenkins Deployer Framework | 15/7/2020 | 17/6/2026 | Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Media (5.9) | 2.1% | — | Openbsd OpensshNetapp AFF A700s FirmwareNetapp Active IQ Unified ManagerNetapp HCI Management Node+5 | 29/6/2020 | 17/6/2026 | The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6… | |
| Modificada | Media (6.5) | 0.85% | — | Octopus Deploy | 19/6/2020 | 17/6/2026 | In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password. | |
| Modificada | Media (5.3) | 4.2% | — | PcreApple MacosGitlabOracle Communications Cloud Native Core Policy+11 | 15/6/2020 | 17/6/2026 | libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. | |
| Modificada | Alta (7.5) | 4.4% | — | SqliteFedoraproject FedoraDebian LinuxOracle Communications Messaging Server+8 | 6/6/2020 | 17/6/2026 | SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. | |
| Modificada | Media (5.9) | 0.81% | — | IBM Urbancode Deploy | 11/5/2020 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 171249. | |
| Modificada | Media (4.3) | 0.98% | — | Octopus Deploy | 28/4/2020 | 17/6/2026 | In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant. | |
| Modificada | Alta (8.8) | 0.97% | — | IBM Urbancode Deploy | 23/4/2020 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0.3.0 and 7.0.4.0 could allow an authenticated user to impersonate another user if the server is configured to enable Distributed Front End (DFE). IBM X-Force ID: 174955. | |
| Modificada | Media (5.5) | 0.31% | — | IBM Urbancode Deploy | 23/4/2020 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250. | |
| Modificada | Media (4.3) | 0.91% | — | IBM Urbancode Deploy | 16/4/2020 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic processes. IBM X-Force ID: 175639. | |
| Modificada | Crítica (9.8) | 7.6% | — | SqliteNetapp Ontap Select Deploy Administration UtilityOracle Communications Network Charging AND ControlOracle Enterprise Manager OPS Center+8 | 9/4/2020 | 17/6/2026 | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement. | |
| Modificada | Alta (7.5) | 4.3% | — | SqliteNetapp Ontap Select Deploy Administration UtilityDebian LinuxCanonical Ubuntu Linux+14 | 9/4/2020 | 17/6/2026 | SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled. |