Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
686 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.26% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric Hyper HistorianAIMitsubishielectric MC Works64AI+1 | 4/7/2024 | 17/6/2026 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric GENESIS32 versions… | |
| Modificada | Media (6) | 0.17% | — | Citrix XenserverCitrix Hypervisor | 13/6/2024 | 17/6/2026 | An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive. | |
| Aplazada | Alta (8.3) | 0.49% | — | Alpitronic HyperchargerAI | 15/5/2024 | 17/6/2026 | If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator. | |
| Aplazada | Media (5.4) | 0.31% | — | Oracle HyperionAI | 25/4/2024 | 17/6/2026 | Unicode transformation vulnerability in Hyperion affecting version 2.0.15. This vulnerability could allow an attacker to send a malicious payload with Unicode characters that will be replaced by ASCII characters. | |
| Aplazada | Media (5.4) | 0.31% | — | Hyperion WEB ServerAI | 25/4/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Hyperion Web Server affecting version 2.0.15. This vulnerability could allow an attacker to execute malicious Javascript code on the client by injecting that code into the URL. | |
| Analizada | Media (5.5) | 0.42% | — | Hyperprog Cdcat | 29/2/2024 | 17/6/2026 | A vulnerability was found in Hyper CdCatalog 2.3.1. It has been classified as problematic. This affects an unknown part of the component HCF File Handler. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Media (4.4) | 0.17% | — | IBM Powervm Hypervisor | 6/2/2024 | 17/6/2026 | IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information. IBM X-Force ID: 269695. | |
| Modificada | Media (4.9) | 0.37% | — | IBM Powervm Hypervisor | 4/2/2024 | 17/6/2026 | IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could reveal sensitive partition data to a system administrator. IBM X-Force ID: 257135. | |
| Modificada | Crítica (9.8) | 1.6% | 💥 PoC | Vercel Hyper | 28/1/2024 | 17/6/2026 | An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. | |
| Modificada | Media (6.5) | 0.32% | — | Hyperledger Ursa | 16/1/2024 | 17/6/2026 | Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model. Notably, a malicious verifier may be able to generate a unique identifier for… | |
| Modificada | Alta (8.1) | 0.28% | — | Hyperledger Ursa | 16/1/2024 | 17/6/2026 | Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a revoked credential to generate a valid… | |
| Modificada | Media (5.3) | 0.43% | — | Hyperledger Ursa | 16/1/2024 | 17/6/2026 | Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds implementations is that the Issuer does not publish a key correctness proof demonstrating that a generated private key is sufficient to meet the unlinkability… | |
| Modificada | Alta (8.8) | 0.63% | — | Hyperledger Aries Cloud Agent | 11/1/2024 | 17/6/2026 | Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation `document.proof` was… | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Poweredge R660 FirmwareDell Poweredge R760 FirmwareDell Poweredge C6620 FirmwareDell Poweredge Mx760c Firmware+122 | 8/12/2023 | 17/6/2026 | Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Modificada | Baja (3.3) | 0.21% | — | Softiron Hypercloud | 5/12/2023 | 17/6/2026 | An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process. In this instance, workloads may be scheduled on these nodes and deploy to a failed or erroneous state, which impacts the availability of these workloads that may be deployed… | |
| Modificada | Media (6.1) | 0.22% | — | Softiron Hypercloud | 5/12/2023 | 17/6/2026 | An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and integrity. This issue only impacts SoftIron… | |
| Modificada | Media (4.4) | 0.24% | — | Softiron Hypercloud | 5/12/2023 | 17/6/2026 | An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability for a user to authenticate against the management plane. An authenticated admin-level user may be able to delete the "admin" or "serveradmin" users, which prevents authentication from subsequently succeeding. This issue… | |
| Modificada | Media (6.5) | 0.52% | — | Hyperledger Fabric | 14/11/2023 | 17/6/2026 | Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called "cross-linking" results in a molecule with a chemical formula that is composed of all atoms of the original two molecules. In Fabric, one can take a block of transactions and cross-link the… | |
| Modificada | Media (6.1) | 0.58% | — | Cisco Hyperflex HX Data Platform | 6/9/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability… | |
| Modificada | Media (5.5) | 0.36% | — | Plannigan Hyper Bump IT | 4/9/2023 | 17/6/2026 | hyper-bump-it is a command line tool for updating the version in project files.`hyper-bump-it` reads a file glob pattern from the configuration file. That is combined with the project root directory to construct a full glob pattern that is used to find files that should be edited. These matched files should be… | |
| Modificada | Media (5.5) | 0.17% | — | Intel Hyperscan Library | 11/8/2023 | 17/6/2026 | Insufficient control flow management in the Hyperscan Library maintained by Intel(R) before version 5.4.1 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.5) | 0.62% | — | Oracle Hyperion | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the… | |
| Modificada | Alta (7.6) | 0.55% | — | Oracle Hyperion Workspace | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Hyperion Workspace product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks… | |
| Modificada | Media (6) | 0.21% | — | Oracle Hyperion Essbase Administration Services | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion… | |
| Modificada | Alta (7.5) | 0.63% | — | IBM Powervm Hypervisor | 15/6/2023 | 17/6/2026 | IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.00 through FW1030.11 could allow an attacker to obtain sensitive information if they gain service access to the HMC. IBM X-Force ID: 247592. |