Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
634 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+3 | 2/10/2019 | 17/6/2026 | A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files. | |
| Modificada | Media (4.3) | 0.81% | — | Jenkins Azure Event Grid Notifier | 25/9/2019 | 17/6/2026 | Jenkins Azure Event Grid Build Notifier Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Alta (7.8) | 0.91% | — | Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Compute Node EUS+35 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.87% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Real Time+30 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (8.8) | 3.9% | — | Metagauss Profilegrid | 3/9/2019 | 17/6/2026 | The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code. | |
| Modificada | Crítica (9.8) | 2.2% | — | Univa Grid Engine | 30/7/2019 | 17/6/2026 | In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890). | |
| Modificada | Crítica (9.8) | 3.1% | — | Datagrid Project Datagrid | 26/7/2019 | 17/6/2026 | The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. | |
| Modificada | Alta (7.5) | 3.5% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+2 | 25/7/2019 | 17/6/2026 | undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api. | |
| Modificada | Crítica (9.8) | 3.0% | — | Redhat UndertowRedhat VirtualizationRedhat Virtualization HostRedhat Jboss Data Grid+2 | 12/6/2019 | 17/6/2026 | A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange) | |
| Modificada | Crítica (9.8) | 3.3% | — | Exagrid Backup Appliance Firmware | 3/6/2019 | 17/6/2026 | ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability, which allows remote attackers to view and retrieve verbose logging information. Files within this directory were observed to contain sensitive run-time information, including Base64 encoded… | |
| Modificada | Media (6.1) | 1.2% | — | Gridea | 13/5/2019 | 17/6/2026 | Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring. | |
| Modificada | Crítica (9.8) | 2.5% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver… | |
| Modificada | Alta (8.8) | 2.1% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric,… | |
| Modificada | Alta (8.8) | 0.95% | — | Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 24/4/2019 | 17/6/2026 | The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric… | |
| Modificada | Media (6.5) | 1.4% | — | Canonical Ubuntu LinuxNvidia Geforce GTX 745 FirmwareNvidia Geforce GTX 750 FirmwareNvidia Geforce GTX 750 TI Firmware+13 | 1/4/2019 | 17/6/2026 | A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability.… | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Boldgrid W3 Total Cache | 1/4/2019 | 17/6/2026 | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data. | |
| Modificada | Alta (8.8) | 2.6% | — | Psigridconnect Telecontrol Gateway Xs-mu FirmwarePsigridconnect Telecontrol Gateway VM FirmwarePsigridconnect Telecontrol Gateway 3G FirmwarePsigridconnect Smart Telecontrol Unit TCG Firmware+1 | 5/3/2019 | 17/6/2026 | PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway XS-MU Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway VM Versions 4.2.21, 5.0.27,… | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Media (5.3) | 8.7% | 💥 Exploit | Vembu Storegrid | 23/2/2019 | 17/6/2026 | In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash. | |
| Modificada | Media (6.1) | 3.3% | 💥 Exploit | Vembu Storegrid | 23/2/2019 | 17/6/2026 | Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php. | |
| Modificada | Media (4.3) | 1.5% | — | Cisco AMP Threat Grid ApplianceCisco AMP Threat Grid Cloud | 24/1/2019 | 17/6/2026 | A vulnerability in Cisco AMP Threat Grid could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to unsafe creation of API keys. An attacker could exploit this vulnerability by using insecure credentials to gain unauthorized access to the affected device. An exploit… | |
| Modificada | Media (6.5) | 7.3% | — | GrafanaRedhat Ceph StorageRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 13/12/2018 | 17/6/2026 | Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions. | |
| Modificada | Crítica (9.8) | 1.6% | — | Netapp Storagegrid Webscale | 14/11/2018 | 17/6/2026 | All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on the same network as the StorageGRID Webscale Admin Node via HTTP or to take over services on the Admin Node. | |
| Modificada | Alta (8.8) | 0.58% | — | Tibco Datasynapse Gridserver Manager | 13/11/2018 | 17/6/2026 | The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an unauthenticated user to perform cross-site request forgery (CSRF). Affected releases are TIBCO Software Inc. TIBCO DataSynapse GridServer Manager: versions… | |
| Modificada | Alta (7.5) | 3.6% | — | Net-snmpNetapp Cloud BackupNetapp Hyper Converged InfrastructureNetapp Storagegrid Webscale+3 | 8/10/2018 | 17/6/2026 | snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. |