Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

872 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.84%—HPE Superdome Flex Server Firmware1/4/202117/6/2026
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following…
ModificadaMedia (5.5)3.3%—Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+1519/3/202117/6/2026
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
ModificadaMedia (5.5)3.0%—Apache PdfboxFedoraproject FedoraOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+1119/3/202117/6/2026
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
ModificadaAlta (8.2)13%—Apache BatikFedoraproject FedoraOracle Agile Engineering Data ManagementOracle Banking Apis+1824/2/202117/6/2026
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
ModificadaAlta (7.5)3.5%—Rockwellautomation Flex IO 1794-aent/b Firmware4/2/202117/6/2026
An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to…
ModificadaAlta (7.5)11%—Apache ActivemqApache ArtemisNetapp Oncommand Workflow AutomationDebian Linux+427/1/202117/6/2026
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no…
ModificadaAlta (7.2)2.4%—Zyxel VPN OrchestratorZyxel ZLDZyxel NSG FirmwareZyxel USG Flex Firmware27/12/202017/6/2026
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38,…
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitZyxel Usg20-vpn FirmwareZyxel Usg20w-vpn FirmwareZyxel Usg40 FirmwareZyxel Usg40w Firmware+2622/12/202017/6/2026
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
ModificadaMedia (6.1)2.1%💥 ExploitFlexmonster Pivot Table & Charts17/12/202017/6/2026
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.
ModificadaMedia (6.1)2.2%💥 ExploitFlexmonster Pivot Table & Charts17/12/202017/6/2026
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
ModificadaMedia (6.1)2.2%💥 ExploitFlexmonster Pivot Table & Charts17/12/202017/6/2026
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.
ModificadaMedia (6.1)2.2%💥 ExploitFlexmonster Pivot Table & Charts17/12/202017/6/2026
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
ModificadaCrítica (9.8)5.3%—Flexense Dupscout9/12/202017/6/2026
A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.
ModificadaMedia (4.8)8.3%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+1328/11/202017/6/2026
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely…
ModificadaAlta (8.8)73%💥 ExploitFlexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or…
ModificadaAlta (8.1)1.8%—Flexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>…
ModificadaMedia (6.5)0.41%—Creativeitem Neoflex Video Subscription System4/11/202017/6/2026
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
ModificadaAlta (7)4.4%—Eclipse JettyNetapp Snap Creator FrameworkNetapp SnapcenterNetapp Vasa Provider+1423/10/202017/6/2026
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared…
ModificadaMedia (6.5)2.0%—Oracle Flexcube Direct Banking21/10/202017/6/2026
Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login). Supported versions that are affected are 12.0.1, 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE…
ModificadaMedia (6.5)1.9%—Oracle Flexcube Direct Banking21/10/202017/6/2026
Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login). Supported versions that are affected are 12.0.1, 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE…
ModificadaMedia (6.5)1.5%—Oracle Flexcube Universal Banking21/10/202017/6/2026
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3.0 and 14.0.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (7.5)4.3%—Rockwellautomation Flex I/O 1794-aent19/10/202017/6/2026
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to…
ModificadaAlta (7.5)4.3%—Rockwellautomation Flex I/O 1794-aent19/10/202017/6/2026
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to…
ModificadaMedia (6.4)0.23%—Lenovo Bladecenter Hs23 FirmwareLenovo Bladecenter Hs23e FirmwareLenovo Compute Node-x440 FirmwareLenovo Flex System X220 Firmware+1414/10/202017/6/2026
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
ModificadaAlta (7.5)4.3%—Rockwellautomation Flex I/O 1794-aent/b Firmware14/10/202017/6/2026
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this…
Orbitaley — Vulnerabilidades