Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2369 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (10)1.4%—Synology Unified ControllerSynology Replication ServiceSyncology Replication Service19/3/202517/6/2026
Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via…
AnalizadaAlta (8.8)0.45%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)0.44%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.8)0.44%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (7.5)0.25%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+211/3/202517/6/2026
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.
AplazadaAlta (8.1)0.21%—Nvidia Hopper HGXAINvidia HGX Management ControllerAI5/3/202517/6/2026
NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges,…
AnalizadaMedia (6.5)0.27%—IBM Controller1/3/202517/6/2026
IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
AnalizadaMedia (5.7)0.10%—Cisco Application Policy Infrastructure Controller26/2/202517/6/2026
A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to a race condition…
AnalizadaMedia (4.4)0.16%—Cisco Application Policy Infrastructure Controller26/2/202517/6/2026
A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient…
AnalizadaMedia (6.7)0.19%—Cisco Application Policy Infrastructure Controller26/2/202517/6/2026
A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient…
AnalizadaMedia (4.8)0.28%—Cisco Application Policy Infrastructure Controller26/2/202517/6/2026
A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper input validation in the web UI. An authenticated…
AnalizadaMedia (6.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
AnalizadaMedia (6.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
AnalizadaAlta (7.5)0.37%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+225/2/202517/6/2026
Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaAlta (8.8)0.61%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+325/2/202517/6/2026
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
AnalizadaAlta (8.2)0.52%—IBM Cognos ControllerIBM Controller19/2/202517/6/2026
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
ModificadaAlta (8)0.42%—IBM Cognos ControllerIBM Controller19/2/202517/6/2026
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the system, caused by improper validation of file contents.
AnalizadaMedia (6.5)0.27%—IBM Cognos ControllerIBM Controller19/2/202517/6/2026
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks.
AnalizadaMedia (5.9)0.20%—IBM Cognos ControllerIBM Controller19/2/202517/6/2026
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaAlta (8.8)0.61%—IBM Cognos ControllerIBM Controller19/2/202517/6/2026
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the unrestricted deserialization of types in the application.
AnalizadaMedia (5.4)0.22%—IBM Cognos ControllerIBM Controller19/2/202517/6/2026
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (8.8)0.36%—IBM Cognos ControllerIBM Controller19/2/202517/6/2026
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
AplazadaAlta (8.1)0.26%—Crowdstrike Falcon Sensor FOR LinuxAICrowdstrike Falcon Kubernetes Admission ControllerAICrowdstrike Falcon Container SensorAI12/2/202517/6/2026
CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection…
AnalizadaAlta (7.5)0.16%—Audiocodes Mediant Session Border Controller7/2/202517/6/2026
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.
AnalizadaMedia (5.1)0.43%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+175/2/202517/6/2026
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 .…