Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

539 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (10)0.93%—Supermicro X11dai-n FirmwareSupermicro X11dac FirmwareSupermicro X11dph-tq FirmwareSupermicro X11dph-i Firmware+33221/9/201917/6/2026
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by…
ModificadaAlta (8.2)2.3%—Supervisord Supervisor10/9/201917/6/2026
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the…
ModificadaCrítica (9.8)4.5%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is…
ModificadaCrítica (9.8)76%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user…
ModificadaAlta (7.2)39%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of…
ModificadaCrítica (9.8)83%💥 ExploitCisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The…
ModificadaAlta (7.5)2.0%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A…
ModificadaAlta (8.8)1.4%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected…
ModificadaAlta (7.5)1.9%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on…
ModificadaAlta (7.2)1.8%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request…
ModificadaAlta (7.2)3.8%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software.…
ModificadaAlta (7.8)0.41%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input…
ModificadaAlta (7.2)3.3%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an affected device. The vulnerability is due to improper…
ModificadaAlta (8.8)3.6%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied…
ModificadaAlta (8.8)2.6%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of command input by…
ModificadaAlta (8.1)1.7%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this…
ModificadaAlta (7.2)3.5%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. An attacker would need to have valid administrator credentials on the…
ModificadaAlta (7.2)2.8%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient…
ModificadaAlta (7.5)2.0%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing…
ModificadaCrítica (9.8)3.6%—Supermicro Superdoctor 51/7/201917/6/2026
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.
ModificadaMedia (6.7)0.61%—Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+2313/5/201917/6/2026
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based…
ModificadaMedia (6.1)0.75%—Bijiadao Waimai Super CMS15/4/201917/6/2026
In waimai Super Cms 20150505, there is an XSS vulnerability via the /admin.php/Foodcat/addsave fcname parameter.
ModificadaMedia (5)0.83%—Omron Cx-supervisor12/2/201917/6/2026
When CX-Supervisor (Versions 3.42 and prior) processes project files and tampers with the value of an offset, an attacker can force the application to read a value outside of an array.
ModificadaAlta (7.3)1.2%—Omron Cx-supervisor12/2/201917/6/2026
An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
ModificadaCrítica (9.8)1.5%—Bijiadao Waimai Super CMS7/2/201917/6/2026
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Injection via the param array parameter to the /index.php?m=public&a=checkemail URI.
Orbitaley — Vulnerabilidades