Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.6% | — | Riverbed Steelcentral Appinternals Dynamic Sampling Agent | 10/3/2022 | 17/6/2026 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be… | |
| Modificada | Crítica (9.8) | 1.3% | — | Riverbed Steelcentral Appinternals Dynamic Sampling Agent | 10/3/2022 | 17/6/2026 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to… | |
| Modificada | Crítica (9.8) | 2.1% | — | Riverbed Steelcentral Appinternals Dynamic Sampling Agent | 10/3/2022 | 17/6/2026 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not have any input validation of the user's input that allowed a malicious payload to be injected. | |
| Modificada | Media (5.3) | 15% | 💥 Exploit | Zohocorp Manageengine Desktop Central | 2/3/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. | |
| Modificada | Media (6.5) | 1.9% | — | Zohocorp Manageengine Desktop Central | 28/1/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. | |
| Modificada | Media (6.5) | 0.90% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+11 | 25/1/2022 | 17/6/2026 | On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have… | |
| Modificada | Alta (7.2) | 1.1% | — | F5 Big-iq Centralized Management | 25/1/2022 | 17/6/2026 | On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.5) | 1.2% | — | Dell EMC Data Protection Central | 24/1/2022 | 17/6/2026 | Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (4.3) | 0.55% | — | Dell EMC Data Protection Central | 24/1/2022 | 17/6/2026 | Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC DNS client processing. A remote malicious user could potentially exploit this vulnerability, allowing port scanning of external hosts. | |
| Modificada | Crítica (9.1) | 24% | — | Zohocorp Manageengine Desktop CentralZohocorp Manageengine Desktop Central Managed Service Providers | 18/1/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. | |
| Modificada | Media (6.5) | 3.6% | — | Zohocorp Manageengine Desktop Central | 10/1/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page. | |
| Modificada | Alta (7.8) | 0.47% | — | Zohocorp Manageengine Desktop Central | 10/1/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined. | |
| Modificada | Alta (8.8) | 7.1% | — | Zohocorp Manageengine Desktop Central | 10/1/2022 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module. | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Desktop Central | 12/12/2021 | 17/6/2026 | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.1) | 8.2% | 💥 Exploit | Apereo Central Authentication Service | 7/12/2021 | 17/6/2026 | Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. | |
| Analizada | Alta (7.5) | 25% | 💥 PoC | Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+26 | 11/11/2021 | 23/9/2026 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network… | |
| Modificada | Crítica (9.8) | 1.2% | — | Archibus WEB Central | 5/10/2021 | 17/6/2026 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session token that could be already in use by another user. It was therefore possible to access the application through a user whose credentials were not known, without any attempt by the testers to modify… | |
| Modificada | Media (6.1) | 0.77% | — | Archibus WEB Central | 5/10/2021 | 17/6/2026 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflowRule.dwr because the data received as input from clients is re-included within the HTTP response returned by the application without adequate validation. In this way, if HTML code or client-side… | |
| Modificada | Alta (8.8) | 0.88% | — | Archibus WEB Central | 5/10/2021 | 17/6/2026 | ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edit-users.axvw, /archibus/schema/ab-data-dictionary-table.axvw, /archibus/schema/ab-schema-add-field.axvw,… | |
| Modificada | Crítica (9.8) | 2.0% | — | Manageengine Desktop Central | 21/9/2021 | 17/6/2026 | Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations. | |
| Modificada | Media (5.4) | 1.1% | — | Microsoft Dynamics 365 Business Central | 15/9/2021 | 10/8/2026 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | |
| Modificada | Alta (8.8) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+11 | 14/9/2021 | 17/6/2026 | BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached… | |
| Modificada | Alta (7.5) | 5.5% | — | Zohocorp Manageengine Desktop Central | 10/9/2021 | 17/6/2026 | Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication. |