Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1294 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.41% | — | Vmware FusionVmware Cloud FoundationVmware WorkstationVmware Esxi | 20/11/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi70U1b-17168206, 6.7 before ESXi670-202011101-SG, 6.5 before ESXi650-202011301-SG), Workstation (15.x before 15.5.7), Fusion (11.x before 11.5.7) contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may… | |
| Modificada | Alta (7.5) | 11% | — | Apache BatikOracle API GatewayOracle Business IntelligenceOracle Communications Application Session Controller+14 | 12/11/2020 | 17/6/2026 | Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | |
| Modificada | Media (4.4) | 0.11% | — | Huawei Fusioncompute | 12/11/2020 | 17/6/2026 | FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak. | |
| Modificada | Media (5.3) | 1.1% | — | Vmware EsxiVmware Cloud FoundationVmware WorkstationVmware Fusion | 20/10/2020 | 17/6/2026 | In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual machine may be able to trigger a memory leak… | |
| Modificada | Alta (7.7) | 0.83% | — | Vmware EsxiVmware Cloud FoundationVmware WorkstationVmware Workstation Player+1 | 20/10/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a… | |
| Modificada | Media (5.8) | 0.80% | — | Vmware Cloud FoundationVmware WorkstationVmware EsxiVmware Fusion | 20/10/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a… | |
| Modificada | Alta (7.8) | 0.22% | — | Huawei Fusionaccess | 12/10/2020 | 17/6/2026 | FusionAccess version 6.5.1 has an improper authorization vulnerability. A command is authorized with incorrect privilege. Attackers with other privilege can execute the command to exploit this vulnerability. This may compromise normal service of the affected product. | |
| Modificada | Alta (7.5) | 1.3% | — | Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+51 | 7/10/2020 | 17/6/2026 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. | |
| Modificada | Crítica (9.1) | 2.9% | — | Fusionauth Samlv2 | 2/10/2020 | 17/6/2026 | FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack". | |
| Modificada | Media (6.5) | 11% | 💥 PoC | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+34 | 19/9/2020 | 17/6/2026 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. | |
| Modificada | Media (6.7) | 0.29% | — | Vmware Fusion | 16/9/2020 | 17/6/2026 | VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick an admin user into executing malicious code on the system where Fusion is installed. | |
| Modificada | Alta (8.8) | 68% | 💥 Exploit | Php-fusion | 3/9/2020 | 17/6/2026 | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE). | |
| Modificada | Media (5.4) | 0.49% | — | Php-fusion | 26/8/2020 | 17/6/2026 | PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php. | |
| Modificada | Media (6.5) | 0.61% | — | Huawei Fusioncompute | 21/8/2020 | 17/6/2026 | FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and information protection. Attackers with low privilege can get some extra information. This can lead to information leak. | |
| Modificada | Crítica (9.1) | 0.78% | — | Huawei Fusioncompute | 17/8/2020 | 17/6/2026 | FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to delete some files and cause some services abnormal. | |
| Modificada | Alta (8.8) | 1.3% | — | Huawei Fusioncompute | 17/8/2020 | 17/6/2026 | FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authenticated attacker to launch a command injection attack. | |
| Modificada | Media (4.4) | 0.22% | — | Huawei Fusioncompute | 14/8/2020 | 17/6/2026 | FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain information. | |
| Modificada | Alta (7.5) | 0.78% | — | Huawei Fusioncompute | 14/8/2020 | 17/6/2026 | FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain information. | |
| Modificada | Media (6.1) | 0.80% | — | Php-fusion | 12/8/2020 | 17/6/2026 | PHP-Fusion 9.03 allows XSS on the preview page. | |
| Modificada | Media (5.4) | 0.55% | — | Php-fusion | 12/8/2020 | 17/6/2026 | PHP-Fusion 9.03 allows XSS via the error_log file. | |
| Modificada | Alta (8.8) | 0.38% | — | Huawei Fusionsphere Openstack | 11/8/2020 | 17/6/2026 | FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protection mechanism. An attacker has to find a way to exploit the vulnerability to conduct directed attacks against the affected product. | |
| Modificada | Alta (7.8) | 0.22% | — | Huawei Fusioncompute | 10/8/2020 | 17/6/2026 | FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service. | |
| Modificada | Media (6.7) | 0.23% | — | Huawei Fusioncompute | 31/7/2020 | 17/6/2026 | Huawei FusionComput 8.0.0 have an improper authorization vulnerability. A module does not verify some input correctly and authorizes files with incorrect access. Attackers can exploit this vulnerability to launch privilege escalation attack. This can compromise normal service. | |
| Modificada | Alta (7.8) | 1.0% | — | Adobe Coldfusion | 17/7/2020 | 17/6/2026 | Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation. | |
| Modificada | Alta (7.8) | 1.0% | — | Adobe Coldfusion | 17/7/2020 | 17/6/2026 | Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation. |