Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1028 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)0.38%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+28014/11/201917/6/2026
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of…
ModificadaMedia (6.7)0.38%—Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+28014/11/201917/6/2026
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local…
ModificadaCrítica (9.8)1.4%—Reviews Module Project Reviews Module26/8/201917/6/2026
The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
ModificadaCrítica (9.8)1.4%—Raml-module-builder Project Raml-module-builder26/8/201917/6/2026
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
ModificadaMedia (4.3)0.77%—Jenkins Pluggable Authentication Module21/5/201917/6/2026
A missing permission check in Jenkins PAM Authentication Plugin 1.5 and earlier, except 1.4.1 in PamSecurityRealm.DescriptorImpl#doTest allowed users with Overall/Read permission to obtain limited information about the file /etc/shadow and the user Jenkins is running as.
ModificadaMedia (5.3)2.8%—Gatship WEB Module17/5/201917/6/2026
GAT-Ship Web Module through 1.30 allows remote attackers to obtain potentially sensitive information via {} in a ws/gatshipWs.asmx/SqlVersion request.
ModificadaMedia (6.7)0.61%—Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+2313/5/201917/6/2026
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based…
ModificadaCrítica (9.8)2.3%—Openmrs-module-htmlformentry10/5/201917/6/2026
OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).
ModificadaCrítica (9.3)1.8%—Jenkins Self-organizing Swarm Modules30/4/201917/6/2026
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.
ModificadaAlta (8.8)2.7%—Gatship WEB Module9/4/201917/6/2026
GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to the server via the "Documents" area. This vulnerability is related to "uploadDocFile.aspx".
ModificadaMedia (5.9)1.0%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Edge Gateway+1028/3/201917/6/2026
On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-blade BIG-IP vCMP guest when processing authorized SNMP requests.
ModificadaMedia (6.8)1.0%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Edge Gateway+1028/3/201917/6/2026
On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, hardware systems with a High-Speed Bridge and using non-default Layer 2 forwarding configurations may experience a lockup of the High-Speed Bridge.
ModificadaAlta (7.5)3.2%—Rockwellautomation Ethernet/ip WEB Server Module 1756-ewebRockwellautomation Ethernet/ip WEB Server Module 1768-eweb27/3/201917/6/2026
Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.005 and earlier. A remote attacker could send a crafted UDP packet to the SNMP service causing a denial-of-service condition to occur until the affected product is…
ModificadaMedia (5.9)1.2%—Siemens Siprotec 5 With CPU Variant Cp100Siemens Siprotec 5 With CPU Variant Cp200Siemens Siprotec 5 With CPU Variant Cp300Siemens En100 Ethernet Module Firmware+521/3/201917/6/2026
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firmware variant MODBUS TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions),…
ModificadaCrítica (9.8)2.9%—Redhat Modulemd10/1/201917/6/2026
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
ModificadaMedia (6.5)4.8%—Fasterxml Jackson-modules-java8Oracle ClusterwareOracle Database ServerOracle Global Lifecycle Management Opatch+220/12/201817/6/2026
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a…
ModificadaMedia (6.5)0.74%—Blinkforhome Sync Module15/12/201817/6/2026
A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable cameras via Wi-Fi, because incident clips (triggered by the motion sensor) are not saved if the attacker's traffic (such as Dot11Deauth) successfully disconnects the Sync Module from the Wi-Fi network.…
ModificadaMedia (6.5)0.73%—Lenovo System Management Module Firmware27/11/201817/6/2026
In System Management Module (SMM) versions prior to 1.06, if an attacker manages to log in to the device OS, the validation of software updates can be circumvented.
ModificadaAlta (8.1)1.1%—Lenovo System Management Module Firmware27/11/201817/6/2026
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.
ModificadaMedia (6.1)0.65%—Lenovo System Management Module Firmware27/11/201817/6/2026
In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.
ModificadaMedia (5.9)0.92%—Lenovo System Management Module Firmware27/11/201817/6/2026
In System Management Module (SMM) versions prior to 1.06, the SMM records hashed passwords to a debug log when user authentication fails.
ModificadaAlta (8.1)0.89%—Lenovo System Management Module Firmware27/11/201817/6/2026
In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow.
ModificadaAlta (8.1)0.87%—Lenovo System Management Module Firmware27/11/201817/6/2026
In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.
ModificadaAlta (8.1)0.57%—Lenovo System Management Module Firmware27/11/201817/6/2026
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.
ModificadaAlta (7.5)0.87%—Lenovo System Management Module Firmware27/11/201817/6/2026
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection.