Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1571 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.31%—Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management AND Operations SystemAI1/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this issue is some unknown functionality of the file /wuser/anyUserBoundHouse.php. The manipulation of the argument huid leads to…
AplazadaMedia (4.7)0.28%—Opera MiniAI21/2/202517/6/2026
Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to impersonate another page and trick a user into providing sensitive data.
AnalizadaMedia (5.3)0.16%—Broadcom Fabric Operating System15/2/202517/6/2026
If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP privsecret / authsecret fields can be exposed in plaintext. The plaintext passwords can be exposed in a configupload capture or a supportsave capture if encryption of passwords is not enabled. An…
AnalizadaAlta (8.6)0.45%—Broadcom Fabric Operating System15/2/202517/6/2026
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the…
AnalizadaAlta (8.1)3.7%—Nvidia Container ToolkitNvidia GPU Operator12/2/202517/6/2026
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of…
AnalizadaAlta (7.5)0.66%—Audiocodes ONE Voice Operations Center7/2/202517/6/2026
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.
AnalizadaMedia (6.1)0.24%—Audiocodes ONE Voice Operations Center7/2/202517/6/2026
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.
AnalizadaAlta (7.5)0.36%—Audiocodes ONE Voice Operations Center7/2/202517/6/2026
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.
AnalizadaAlta (7.5)0.23%—Dell Data Domain Operating System4/2/202517/6/2026
Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote attacker could potentially exploit this vulnerability, leading to Information tampering.
AnalizadaAlta (7.8)0.14%—Dell Data Domain Operating System1/2/202517/6/2026
Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege.
AnalizadaMedia (4.9)0.39%—Dell Data Domain Operating System1/2/202517/6/2026
Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer Overflow vulnerability in the RestAPI. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
AnalizadaAlta (7.1)0.18%—Dell Data Domain Operating System1/2/202517/6/2026
Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could potentially exploit this vulnerability to gain unauthorized overwrite of OS files stored on the server filesystem. Exploitation could lead to denial of service.
AplazadaAlta (7.1)0.13%—Operationsissuu Issuu PanelAI31/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in operationsissuu Issuu Panel issuu-panel allows Stored XSS.This issue affects Issuu Panel: from n/a through <= 2.1.1.
AnalizadaMedia (6.5)0.56%—Vmware Aria OperationsVmware Cloud Foundation30/1/202517/6/2026
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
AnalizadaMedia (4.8)0.40%—Vmware Aria Operations FOR LogsVmware Cloud Foundation30/1/202517/6/2026
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
AnalizadaMedia (5.4)0.33%—Vmware Aria Operations FOR LogsVmware Cloud Foundation30/1/202517/6/2026
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.
AnalizadaCrítica (9)0.67%—Vmware Aria Operations FOR LogsVmware Cloud Foundation30/1/202517/6/2026
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
AnalizadaAlta (7.7)0.68%—Vmware Aria Operations FOR LogsVmware Cloud Foundation30/1/202517/6/2026
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
AplazadaAlta (8.2)0.22%—Redhat Openshift-gitops-operator-containerAIArgoproj ArgocdAI28/1/202526/6/2026
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out…
AnalizadaMedia (6.5)0.33%—Nvidia Container ToolkitNvidia GPU Operator28/1/202517/6/2026
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this…
AnalizadaAlta (8.4)0.67%—Nvidia Container ToolkitNvidia GPU Operator28/1/202517/6/2026
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of…
AnalizadaAlta (7.6)1.1%—Nvidia Container ToolkitNvidia GPU Operator28/1/202517/6/2026
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
AnalizadaAlta (7.5)0.21%—IBM MQ OperatorIBM Supplied MQ Advanced Container Images27/1/202517/6/2026
IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaCrítica (9.1)0.59%—Oracle Hospitality Opera 521/1/202517/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.20, 5.6.25.8, 5.6.26.6 and 5.6.27.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
AplazadaMedia (5.3)0.72%—KarmadaAIKarmadactlAIKarmada-operatorAI3/1/202517/6/2026
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resource definitions(CRDs)…