Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.84% | — | HPE Superdome Flex Server Firmware | 1/4/2021 | 17/6/2026 | A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following… | |
| Modificada | Media (5.5) | 3.3% | — | Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+15 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | |
| Modificada | Media (5.5) | 3.0% | — | Apache PdfboxFedoraproject FedoraOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+11 | 19/3/2021 | 17/6/2026 | A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. | |
| Modificada | Alta (8.2) | 13% | — | Apache BatikFedoraproject FedoraOracle Agile Engineering Data ManagementOracle Banking Apis+18 | 24/2/2021 | 17/6/2026 | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modificada | Alta (7.5) | 3.5% | — | Rockwellautomation Flex IO 1794-aent/b Firmware | 4/2/2021 | 17/6/2026 | An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to… | |
| Modificada | Alta (7.5) | 11% | — | Apache ActivemqApache ArtemisNetapp Oncommand Workflow AutomationDebian Linux+4 | 27/1/2021 | 17/6/2026 | The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no… | |
| Modificada | Alta (7.2) | 2.4% | — | Zyxel VPN OrchestratorZyxel ZLDZyxel NSG FirmwareZyxel USG Flex Firmware | 27/12/2020 | 17/6/2026 | Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38,… | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa💥 Exploit | Zyxel Usg20-vpn FirmwareZyxel Usg20w-vpn FirmwareZyxel Usg40 FirmwareZyxel Usg40w Firmware+26 | 22/12/2020 | 17/6/2026 | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges. | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Crítica (9.8) | 5.3% | — | Flexense Dupscout | 9/12/2020 | 17/6/2026 | A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack. | |
| Modificada | Media (4.8) | 8.3% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+13 | 28/11/2020 | 17/6/2026 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely… | |
| Modificada | Alta (8.8) | 73% | 💥 Exploit | Flexdotnetcms Project Flexdotnetcms | 12/11/2020 | 17/6/2026 | An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or… | |
| Modificada | Alta (8.1) | 1.8% | — | Flexdotnetcms Project Flexdotnetcms | 12/11/2020 | 17/6/2026 | Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>… | |
| Modificada | Media (6.5) | 0.41% | — | Creativeitem Neoflex Video Subscription System | 4/11/2020 | 17/6/2026 | Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings) | |
| Modificada | Alta (7) | 4.4% | — | Eclipse JettyNetapp Snap Creator FrameworkNetapp SnapcenterNetapp Vasa Provider+14 | 23/10/2020 | 17/6/2026 | In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared… | |
| Modificada | Media (6.5) | 2.0% | — | Oracle Flexcube Direct Banking | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login). Supported versions that are affected are 12.0.1, 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE… | |
| Modificada | Media (6.5) | 1.9% | — | Oracle Flexcube Direct Banking | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login). Supported versions that are affected are 12.0.1, 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE… | |
| Modificada | Media (6.5) | 1.5% | — | Oracle Flexcube Universal Banking | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3.0 and 14.0.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 4.3% | — | Rockwellautomation Flex I/O 1794-aent | 19/10/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to… | |
| Modificada | Alta (7.5) | 4.3% | — | Rockwellautomation Flex I/O 1794-aent | 19/10/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to… | |
| Modificada | Media (6.4) | 0.23% | — | Lenovo Bladecenter Hs23 FirmwareLenovo Bladecenter Hs23e FirmwareLenovo Compute Node-x440 FirmwareLenovo Flex System X220 Firmware+14 | 14/10/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected. | |
| Modificada | Alta (7.5) | 4.3% | — | Rockwellautomation Flex I/O 1794-aent/b Firmware | 14/10/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this… |