Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1067 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.
ModificadaAlta (7.5)1.0%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application. This is a digs-- calculation.
ModificadaAlta (7.5)1.0%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation fault and crash the application. This is a "- (digs < 1 ? 1 :…
ModificadaAlta (7.5)1.0%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application. This is a "- digs" subtraction.
ModificadaCrítica (9.1)1.0%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnumber.c in order to corrupt memory or crash the application.
ModificadaAlta (7.5)1.2%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.
ModificadaCrítica (9.8)2.0%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c in order to gain control of the flow of execution.
ModificadaAlta (7.5)1.2%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in trip_gen in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.
ModificadaAlta (7.5)1.2%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to emit_trip in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.
ModificadaAlta (7.5)1.2%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero.
ModificadaAlta (7.5)1.0%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.
ModificadaAlta (7.5)1.1%—Fisglobal Gt.mYottadb15/4/202217/6/2026
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of parameter validation in calls to memcpy in check_and_set_timeout in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.
ModificadaMedia (5.4)0.60%—Coins-global Coins Construction Cloud14/4/202217/6/2026
An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a task, it is possible to store malicious JavaScript code in the task description. This is later executed when it is reflected back to the user.
ModificadaMedia (5.4)0.60%—Coins-global Coins Construction Cloud14/4/202217/6/2026
An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack.
ModificadaAlta (7.4)0.62%—Dcnglobal S4600-10p-si Firmware5/4/202217/6/2026
An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands as root via shell metacharacters in the…
ModificadaMedia (4.6)0.39%💥 PoCGlobalsuzuki Suzuki Connect29/3/202217/6/2026
Suzuki Connect v1.0.15 allows attackers to tamper with displayed messages via spoofed CAN messages.
ModificadaAlta (7.5)0.81%—Globalprotect-openconnect Project Globalprotect-openconnect22/3/202217/6/2026
GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect compatible server, the attack can redirect…
ModificadaCrítica (9.8)1.6%—Globalprotect-openconnect Project Globalprotect-openconnect22/3/202217/6/2026
GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=<script>` parameter.
ModificadaCrítica (9.8)3.3%—Dcnglobal Dcme-520 Firmware18/3/202217/6/2026
DCN Firewall DCME-520 was discovered to contain a remote command execution (RCE) vulnerability via the host parameter in the file /system/tool/ping.php.
ModificadaAlta (7.5)0.95%—Dcnglobal Dcme-520 Firmware18/3/202217/6/2026
DCN Firewall DCME-520 was discovered to contain an arbitrary file download vulnerability via the path parameter in the file /audit/log/log_management.php.
ModificadaMedia (4.8)0.79%—Jenkins Global-build-stats15/3/202217/6/2026
Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Global Build Stats' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
ModificadaAlta (7.5)4.9%💥 PoCFasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+3211/3/202217/6/2026
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
ModificadaMedia (6.1)0.73%—HPE Oneview Global Dashboard24/2/202217/6/2026
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
ModificadaMedia (6.1)0.56%—HPE Oneview Global Dashboard24/2/202217/6/2026
A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
ModificadaMedia (5.5)0.22%—Paloaltonetworks Globalprotect10/2/202217/6/2026
An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect App 5.2 versions earlier than 5.2.9 on…