Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.5% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and… | |
| Modificada | Crítica (9.8) | 1.8% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is the result of a bad set up and can be mitigated by appropriately configuring ROS and/or applying custom patches as appropriate. Currently,… | |
| Modificada | Crítica (9.8) | 1.7% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Credentials to such wireless interface default to well known and widely spread users (omitted) and passwords (omitted). This information is also… | |
| Modificada | Crítica (9.8) | 1.4% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Credentials to such wireless Access Point default to well known and widely spread SSID (MiR_RXXXX) and passwords (omitted). This information is… | |
| Modificada | Media (6.7) | 0.34% | — | Lenovo 130-14ast FirmwareLenovo 130-14ikb FirmwareLenovo 130-15ast FirmwareLenovo 130-15ikb Firmware+168 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. | |
| Modificada | Media (6.7) | 0.30% | — | HPE Superdome Flex Server Firmware | 19/5/2020 | 17/6/2026 | A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Flex Server version 3.25.46 or later to resolve this issue. | |
| Modificada | Media (6.1) | 7.1% | — | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+3 | 14/5/2020 | 17/6/2026 | In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue. | |
| Modificada | Crítica (9.8) | 6.8% | — | Apache CamelOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking | 14/5/2020 | 17/6/2026 | Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. | |
| Modificada | Crítica (9.8) | 5.7% | — | Apache CamelOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base PlatformOracle Flexcube Private Banking | 14/5/2020 | 17/6/2026 | Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. | |
| Modificada | Alta (7.5) | 14% | — | Apache CamelOracle Communications Diameter Intelligence HUBOracle Communications Diameter Signaling RouterOracle Enterprise Manager Base Platform+1 | 14/5/2020 | 17/6/2026 | Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0. | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Modificada | Alta (8.8) | 0.51% | — | Commscope Ruckus Zoneflex R500 Firmware | 5/5/2020 | 17/6/2026 | CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen. | |
| Modificada | Media (6.1) | 0.70% | — | Commscope Ruckus Zoneflex R500 Firmware | 5/5/2020 | 17/6/2026 | Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field. | |
| Modificada | Alta (8.1) | 0.62% | — | Commscope Ruckus Zoneflex R500 Firmware | 5/5/2020 | 17/6/2026 | A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks. | |
| Modificada | Crítica (9.8) | 7.3% | — | Dom4j Project Dom4jOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Banking Platform+34 | 1/5/2020 | 25/8/2026 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. | |
| Modificada | Baja (3.7) | 8.1% | 💥 PoC | Apache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+42 | 27/4/2020 | 17/6/2026 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 | |
| Modificada | Media (5.5) | 2.7% | — | Apache TikaOracle Flexcube Private BankingOracle Primavera UnifierOracle Webcenter Portal+1 | 27/4/2020 | 17/6/2026 | A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later.… | |
| Modificada | Alta (7.5) | 1.8% | — | Flexera Flexnet Publisher | 21/4/2020 | 17/6/2026 | A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can repeatedly send messages of that type to… | |
| Modificada | Alta (7.5) | 1.3% | — | Flexera Flexnet Publisher | 21/4/2020 | 17/6/2026 | A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a particular flag set in the original message,… | |
| Modificada | Media (6.3) | 0.90% | — | Oracle Flexcube Core Banking | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications (component: Transaction Processing). The supported version that is affected is 4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Core… | |
| Modificada | Media (6.1) | 0.69% | — | Hms-networks Ewon Flexy FirmwareHms-networks Ewon Cosy Firmware | 8/4/2020 | 17/6/2026 | A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful. | |
| Modificada | Crítica (9.8) | 3.7% | — | Lenovo B50-10 FirmwareLenovo Flex 2 Pro-15 FirmwareLenovo Edge 15 FirmwareLenovo Flex 3-1470 Firmware+23 | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code… | |
| Modificada | Media (5.5) | 2.9% | — | Apache TikaOracle Business Process Management SuiteOracle Communications Messaging ServerOracle Flexcube Private Banking+2 | 23/3/2020 | 17/6/2026 | A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. | |
| Modificada | Media (5.5) | 3.0% | — | Apache TikaOracle Business Process Management SuiteOracle Communications Messaging ServerOracle Flexcube Private Banking+2 | 23/3/2020 | 17/6/2026 | A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. | |
| Modificada | Alta (7.2) | 1.6% | — | Arris Ruckus Zoneflex R500 Firmware | 29/1/2020 | 17/6/2026 | Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring. |