Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 1.8% | — | Oracle Solaris | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may… | |
| Modificada | Alta (7.8) | 0.34% | — | Arista Cloudvision Portal | 19/12/2019 | 17/6/2026 | In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. This vulnerability can potentially enable authenticated users with read-only access to take actions… | |
| Modificada | Media (4.9) | 0.49% | — | Arista Cloudvision Portal | 19/12/2019 | 17/6/2026 | In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable mode passwords which are different from… | |
| Modificada | Alta (7.5) | 4.1% | — | WiresharkOpensuse LeapOracle SolarisOracle ZFS Storage Appliance+1 | 5/12/2019 | 17/6/2026 | In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection. | |
| Modificada | Media (6.5) | 0.92% | — | Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+774 | 14/11/2019 | 17/6/2026 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.5) | 4.7% | 💥 PoC | Golang GODebian LinuxFedoraproject FedoraRedhat Developer Tools+7 | 24/10/2019 | 17/6/2026 | Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates. | |
| Analizada | Alta (8.8) | 13% | ⚠ Explotación activa💥 Exploit | Oracle Solaris | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is… | |
| Modificada | Baja (1.8) | 0.37% | — | Oracle Solaris | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: LDAP Library). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks… | |
| Modificada | Baja (3.6) | 0.33% | — | Oracle Solaris | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: SMF services & legacy daemons). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.… | |
| Modificada | Media (5.3) | 0.31% | — | Oracle Solaris | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the… | |
| Modificada | Crítica (9.8) | 11% | 💥 PoC | Connect2id Nimbus Jose+jwtApache HadoopOracle Communications Cloud Native Core Security Edge Protection ProxyOracle Communications Pricing Design Center+11 | 15/10/2019 | 17/6/2026 | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass. | |
| Modificada | Media (5.9) | 0.67% | — | Arista Extensible Operating System | 10/10/2019 | 17/6/2026 | A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on route updates and in turn potentially… | |
| Modificada | Media (6.5) | 4.3% | — | SqliteNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Oncommand Insight+16 | 9/9/2019 | 17/6/2026 | In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner." | |
| Modificada | Alta (7.5) | 5.4% | — | PythonFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+6 | 6/9/2019 | 7/10/2026 | An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could… | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Media (6.5) | 0.61% | — | Arista EOS | 15/8/2019 | 17/6/2026 | Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled. | |
| Modificada | Media (6.5) | 0.77% | — | Arista Cloudvision Portal | 15/8/2019 | 17/6/2026 | Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions. | |
| Modificada | Alta (8.1) | 2.7% | 💥 PoC | Google AndroidApple Iphone OSApple MAC OS XApple Tvos+143 | 14/8/2019 | 17/6/2026 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the… | |
| Modificada | Alta (7.5) | 5.0% | — | OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 26/7/2019 | 17/6/2026 | An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL… | |
| Modificada | Media (4.9) | 3.4% | — | OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 26/7/2019 | 17/6/2026 | An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from… | |
| Modificada | Alta (8.8) | 0.42% | — | Oracle Solaris | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: LDAP Client Tools). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle… | |
| Modificada | Alta (7.5) | 1.3% | — | Oracle Solaris | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFS to compromise Oracle Solaris. Successful attacks of this vulnerability… | |
| Modificada | Alta (8.8) | 0.41% | — | Oracle Solaris | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise… | |
| Modificada | Alta (7.3) | 0.48% | — | Oracle Solaris | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Gnuplot). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.… |