Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 4.7% | — | Nagios FusionNagios XI | 24/5/2021 | 17/6/2026 | Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root. | |
| Modificada | Alta (8.8) | 26% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination. | |
| Modificada | Crítica (9.8) | 3.6% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code. | |
| Modificada | Media (6.1) | 10% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS. | |
| Modificada | Crítica (9.8) | 6.4% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php. | |
| Modificada | Crítica (9.8) | 9.1% | — | Nagios Fusion | 24/5/2021 | 17/6/2026 | Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php. | |
| Modificada | Crítica (9.8) | 2.4% | — | Nagios FusionNagios XI | 24/5/2021 | 17/6/2026 | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh. | |
| Modificada | Alta (8.1) | 1.5% | — | Fusionpbx | 20/5/2021 | 17/6/2026 | Directory Traversal vulnerability in FusionPBX 4.5.7, which allows a remote malicious user to delete folders on the system via the folder variable to app/edit/folderdelete.php. | |
| Modificada | Media (4.3) | 0.99% | — | Fusionpbx | 20/5/2021 | 17/6/2026 | Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php. | |
| Modificada | Media (6.5) | 1.2% | — | Fusionpbx | 20/5/2021 | 17/6/2026 | A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.via the (1) folder, (2) filename, and (3) newfilename variables in app\edit\filerename.php. | |
| Modificada | Media (6.1) | 0.72% | — | Fusionpbx | 20/5/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php. | |
| Modificada | Media (6.1) | 0.69% | — | Fusionpbx | 20/5/2021 | 17/6/2026 | Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\device_imports.php. | |
| Modificada | Media (6.1) | 0.70% | — | Php-fusion Phpfusion | 29/4/2021 | 17/6/2026 | CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML | |
| Modificada | Media (6.5) | 1.3% | — | Fusionauth Saml V2 | 22/4/2021 | 17/6/2026 | FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely. | |
| Modificada | Media (5.4) | 37% | 💥 Exploit | Adobe Coldfusion | 15/4/2021 | 17/6/2026 | Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An attacker could abuse this vulnerability to execute arbitrary JavaScript code in context of… | |
| Modificada | Media (4.8) | 9.9% | 💥 PoC | Apache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+56 | 13/4/2021 | 7/10/2026 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling… | |
| Modificada | Alta (8.2) | 13% | — | Apache BatikFedoraproject FedoraOracle Agile Engineering Data ManagementOracle Banking Apis+18 | 24/2/2021 | 17/6/2026 | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modificada | Media (6.3) | 1.4% | — | Fusioncharts Apexcharts | 9/2/2021 | 17/6/2026 | The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields. | |
| Modificada | Alta (7.8) | 0.23% | — | Huawei Imaster Mae-mHuawei ManageoneHuawei Network Functions Virtualization FusionsphereHuawei Smc2.0 Firmware | 6/2/2021 | 17/6/2026 | There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne versions… | |
| Modificada | Alta (8.3) | 1.4% | — | Oracle Advanced Networking OptionOracle Adaptive Access ManagerOracle Data IntegratorOracle Enterprise Manager FOR Fusion Applications+2 | 20/1/2021 | 17/6/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human… | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Php-fusion Phpfusion | 13/1/2021 | 17/6/2026 | PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim. | |
| Modificada | Media (6.5) | 0.91% | — | Php-fusion | 3/1/2021 | 17/6/2026 | login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration. | |
| Analizada | Media (6.5) | 0.38% | — | Vmware WorkstationVmware EsxiVmware Fusion | 21/12/2020 | 17/6/2026 | VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal… | |
| Modificada | Alta (7.8) | 0.22% | — | Huawei Fusioncompute | 1/12/2020 | 17/6/2026 | FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful exploit will cause privilege escalation. | |
| Modificada | Alta (7.2) | 1.0% | — | Huawei Fusioncompute | 1/12/2020 | 17/6/2026 | Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to cause the attackers to obtain higher privilege. |