Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1028 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.56%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Semg9811 FirmwareHuawei Usg9500 Firmware22/6/202117/6/2026
There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00,…
ModificadaMedia (6.5)0.58%—Huawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 FirmwareHuawei Secospace Usg6600 Firmware+127/5/202117/6/2026
There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise the normal service of the…
ModificadaAlta (8.1)0.93%—Oracle Financials Common Modules22/4/202117/6/2026
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Advanced Global Intercompany). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common…
ModificadaMedia (6.5)0.83%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+88/4/202117/6/2026
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions…
ModificadaMedia (5.3)1.4%—Openresty Lua-nginx-module6/4/202117/6/2026
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
ModificadaAlta (7.5)0.73%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6600 FirmwareHuawei Nip6800 Firmware+322/3/202117/6/2026
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Module, NGFW Module,…
ModificadaAlta (7.5)0.73%—Huawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Nip6800 Firmware+422/3/202117/6/2026
There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft many specific packets. Successful exploit may cause some services to be abnormal. Affected products include some versions of NGFW Module, NIP6300, NIP6600,…
ModificadaAlta (7.5)1.5%—Varnish-cache Varnish-modulesVarnish-cache Varnish-modules KlarlackFedoraproject Fedora16/3/202117/6/2026
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure…
ModificadaCrítica (9.8)1.7%—Spnego Http Authentication Module Project Spnego Http Authentication Module8/3/202117/6/2026
In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentication. This is fixed in version 1.1.1 of…
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…
ModificadaCrítica (9.8)3.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3…
ModificadaAlta (7.3)0.30%—Intel Optane DC Persistent Memory Module Management17/2/202117/6/2026
Uncontrolled search path in the Intel(R) Optane(TM) DC Persistent Memory installer for Windows* before version 1.00.00.3506 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.34%—Soundresearch Dchu Model Software Component Modules13/1/202117/6/2026
The SECOMN service in Sound Research DCHU model software component modules (APO) through 2.0.9.17, delivered on HP Windows 10 computers, may allow escalation of privilege via a fake DLL. (As a resolution, Windows Update is being submitted for all affected products to update to 2.0.9.18 or later.)
ModificadaMedia (6)0.30%—Trustedcomputinggroup Trusted Platform Module18/11/202017/6/2026
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.
ModificadaMedia (6.4)0.21%—AMD Trusted Platform Modules Reference12/11/202017/6/2026
The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be compromised. AMD believes that the attack requires physical access of the device because the power…
ModificadaMedia (4.9)0.91%—SAP Process Integration (pgp Module - Business-to-business ADD ON)10/11/202017/6/2026
SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be used to read messages processed by the module leading to Information Disclosure.
ModificadaMedia (5.5)0.27%—Vivo Frame Touch Module10/11/202017/6/2026
The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.
ModificadaMedia (6.1)0.64%—Lenovo Integrated Management Module 215/9/202017/6/2026
A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller (BMC) web interface during an internal security review. This vulnerability could allow JavaScript code to be executed in…
ModificadaMedia (6.1)0.67%—IBM Bladecenter Advanced Management Module Firmware15/9/202017/6/2026
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web…
ModificadaMedia (5.5)0.33%—Intel Server Board S2600wt FirmwareIntel Server System R1000wt FirmwareIntel Server System R2000wt FirmwareIntel Server Board S2600cw+1413/8/202017/6/2026
Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (8.8)0.71%—Intel Server Board S2600wt FirmwareIntel Server System R1000wt FirmwareIntel Server System R2000wt FirmwareIntel Server Board S2600cw+1413/8/202017/6/2026
Heap-based buffer overflow in the firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaAlta (8.8)0.35%—Intel Server Board S2600wt FirmwareIntel Server System R1000wt FirmwareIntel Server System R2000wt FirmwareIntel Server Board S2600cw+1413/8/202017/6/2026
Incorrect execution-assigned permissions in the file system for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.35%—Intel Server Board S2600wt FirmwareIntel Server System R1000wt FirmwareIntel Server System R2000wt FirmwareIntel Server Board S2600cw+1413/8/202017/6/2026
Heap-based overflow for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.35%—Intel Server Board S2600wt FirmwareIntel Server System R1000wt FirmwareIntel Server System R2000wt FirmwareIntel Server Board S2600cw+1413/8/202017/6/2026
Buffer copy without checking size of input for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.3)0.61%—Intel Server Board S2600wt FirmwareIntel Server System R1000wt FirmwareIntel Server System R2000wt FirmwareIntel Server Board S2600cw+1413/8/202017/6/2026
Cross-site scripting for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Orbitaley — Vulnerabilidades