Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.5) | 0.24% | — | Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Product Data ManagementSiemens Omnivise T3000 Terminal Server+2 | 2/8/2024 | 17/6/2026 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions), Omnivise T3000 Terminal… | |
| Aplazada | Crítica (9.8) | 2.4% | 💥 Exploit | Intelight X-1l Traffic Controller MaxtimeAI | 22/7/2024 | 17/6/2026 | An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component. | |
| Aplazada | Media (4.6) | 0.19% | — | Gallagher Controller 6000AIGallagher Controller 7000AIGallagher Aperio Communication HUBAI | 11/7/2024 | 17/6/2026 | Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the Controller 6000 and 7000 can lead to secured door locks connected via Aperio Communication Hubs to momentarily allow free access. This issue affects: Gallagher Controller 6000 and 7000 9.10 prior to… | |
| Aplazada | Media (6.3) | 0.17% | — | Controller 6000AIController 7000AI | 11/7/2024 | 17/6/2026 | External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to perform arbitrary code execution. This issue affects: 9.10 prior to vCR9.10.240520a (distributed in 9.10.1268(MR1)), 9.00 prior to vCR9.00.240521a (distributed in… | |
| Aplazada | Media (6.8) | 0.31% | — | Gallagher Controller 6000AIGallagher Controller 7000AI | 11/7/2024 | 17/6/2026 | External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated user to modify device I/O connections leading to unexpected behavior that in some circumstances could compromise site physical security controls. Gallagher recommend the… | |
| Analizada | Media (5.1) | 0.55% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | |
| Analizada | Alta (7.2) | 0.76% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler | |
| Modificada | Media (5.3) | 0.43% | — | Aimeos Frontend Controller | 2/7/2024 | 17/6/2026 | aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn't reset the payment status of a user's basket after the user completes a purchase. Versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and… | |
| Modificada | Media (5.5) | 0.48% | — | Aimeos Project Ai-controller-frontend | 2/7/2024 | 17/6/2026 | aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors to remove admin group and locale configuration in the Aimeos backend. Versions 2020.10.13, 2021.10.6, 2022.10.3,… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Aplazada | Alta (8.8) | 0.59% | — | Istar Door ControllersAI | 6/6/2024 | 17/6/2026 | The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access | |
| Aplazada | Media (6.7) | 0.16% | — | Intel Ethernet Controller Administrative ToolsAI | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.20% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.5) | 0.59% | — | Shiftcontroller Employee Shift SchedulingAI | 16/5/2024 | 17/6/2026 | The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_session`-cookie in versions up to, and including, 4.9.57. This makes it possible for an authenticated attacker with contributor access-level or above to inject a PHP Object. No… | |
| Aplazada | Media (5.1) | 0.21% | — | Fluxcd Source-controllerAIKubernetesAI | 15/5/2024 | 17/6/2026 | The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps toolkit. Prior to version 1.2.5, when… | |
| Analizada | Alta (7.5) | 0.59% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.1) | 0.31% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Media (6.5) | 0.46% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of non-contiguous randomized bytes. Under rare conditions,… | |
| Analizada | Alta (8) | 0.58% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.9) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not… | |
| Analizada | Media (4.7) | 0.27% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+18 | 8/5/2024 | 17/6/2026 | When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.8) | 0.35% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938. | |
| Analizada | Media (5.3) | 0.54% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By… | |
| Analizada | Alta (7.2) | 0.50% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 196643. |