Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 8.1% | 💥 Exploit | Christianwebministries Proclaim | 22/2/2018 | 17/6/2026 | Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. | |
| Modificada | Media (6.5) | 1.4% | — | HP Moonshot Remote Console AdministratorHP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware | 15/2/2018 | 17/6/2026 | A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | HP Smart Storage Administrator | 15/2/2018 | 17/6/2026 | A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found. | |
| Modificada | Alta (8.8) | 2.8% | — | Infinispan | 15/2/2018 | 17/6/2026 | It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks. | |
| Modificada | Media (5.3) | 0.89% | — | Lenovo Xclarity Administrator | 30/11/2017 | 17/6/2026 | A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed. | |
| Modificada | Alta (8.8) | 1.4% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified… | |
| Modificada | Alta (8.8) | 1.2% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving… | |
| Modificada | Media (6.1) | 0.83% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the… | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain… | |
| Modificada | Alta (8.8) | 1.0% | — | Lenovo Xclarity Administrator | 22/9/2017 | 17/6/2026 | Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system. | |
| Modificada | Media (6.7) | 0.32% | — | Lenovo Xclarity Administrator | 22/9/2017 | 17/6/2026 | An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2. | |
| Modificada | Media (4.2) | 0.41% | — | Fedoraproject 389 Administration Server | 28/8/2017 | 17/6/2026 | Multiple insecure Temporary File vulnerabilities in 389 Administration Server before 1.1.38. | |
| Modificada | Alta (7.8) | 0.40% | — | Lenovo Xclarity Administrator | 20/6/2017 | 17/6/2026 | In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (5.5) | 0.32% | — | Miniupnp Project Minissdpd | 24/3/2017 | 17/6/2026 | The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (invalid free and daemon crash) via vectors related to error handling. | |
| Modificada | Media (5.5) | 0.32% | — | Miniupnp Project Minissdpd | 24/3/2017 | 17/6/2026 | The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (out-of-bounds memory access and daemon crash) via vectors involving a negative length value. | |
| Modificada | Crítica (9.8) | 1.1% | — | Lenovo Xclarity Administrator | 1/3/2017 | 17/6/2026 | Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user. | |
| Modificada | Alta (7.5) | 1.9% | — | Netapp Ontap Select Deploy Administration Utility | 1/3/2017 | 17/6/2026 | The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.1) | 0.97% | — | EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop | 23/1/2017 | 17/6/2026 | EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.7SP3, prior to P02; and EMC Documentum Capital Projects Version 1.9, prior to P30 and Version 1.10, prior to P17; and EMC Documentum Administrator Version 7.0, Version 7.1, and Version 7.2 prior to… | |
| Modificada | Alta (7) | 0.30% | — | Lenovo Xclarity Administrator | 12/1/2017 | 17/6/2026 | Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords for internal administrative LXCA accounts with temporary passwords that are… | |
| Analizada | Alta (7) | 84% | ⚠ Explotación activa💥 Exploit | Canonical Ubuntu LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 10/11/2016 | 17/6/2026 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW." | |
| Modificada | Alta (8.8) | 5.1% | — | Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+7 | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index… | |
| Modificada | Media (6.3) | 1.3% | — | EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop | 23/6/2016 | 17/6/2026 | EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary… | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | Watchguard Panda Endpoint Administration Agent | 18/4/2016 | 17/6/2026 | Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by modifying an executable module. | |
| Modificada | Media (4.9) | 8.9% | 💥 Exploit | Dell Openmanage Server Administrator | 12/4/2016 | 17/6/2026 | Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file parameter to ViewFile. |