Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
614 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Emcosoftware MSI Package BuilderEmcosoftware Network InventoryEmcosoftware Network Software ScannerEmcosoftware Ping Monitor+4 | 23/5/2022 | 9/7/2026 | Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows… | |
| Modificada | Crítica (9.8) | 1.7% | — | Bdtask Multi Store Inventory Management System | 20/5/2022 | 17/6/2026 | Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request. | |
| Modificada | Alta (7.5) | 1.5% | — | Bdtask Multi Store Inventory Management System | 20/5/2022 | 17/6/2026 | Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pharmacy Sales AND Inventory System Project Pharmacy Sales AND Inventory System | 13/5/2022 | 17/6/2026 | Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=. | |
| Modificada | Media (6.5) | 0.30% | — | Hcltech Bigfix Inventory | 6/5/2022 | 17/6/2026 | This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause a victim's browser to emit an HTTP request to an arbitrary URL in the application. | |
| Modificada | Media (6.5) | 0.36% | — | Hcltech Bigfix Inventory | 6/5/2022 | 17/6/2026 | There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and system blocked victim's account. | |
| Modificada | Alta (7.8) | 1.6% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 19/4/2022 | 17/6/2026 | A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (5) | 0.32% | — | Mini-inventory-and-sales-management-system Project Mini-inventory-and-sales-management-system | 4/3/2022 | 17/6/2026 | Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items. | |
| Modificada | Alta (7.5) | 1.7% | — | TraefikOracle Communications Unified Inventory Management | 17/2/2022 | 17/6/2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a… | |
| Modificada | Alta (7.8) | 0.25% | — | Snowsoftware Snow Inventory Java Scanner | 16/2/2022 | 17/6/2026 | A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0 | |
| Modificada | Media (5.5) | 0.23% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+20 | 11/2/2022 | 17/6/2026 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health… | |
| Modificada | Media (5.4) | 0.78% | — | Factorfx OCS Inventory | 11/2/2022 | 9/7/2026 | OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manipulate the name of some device on your computer, such as a printer, replacing the device name with some malicious code that allows the execution of Stored Cross-site Scripting (XSS). | |
| Modificada | Alta (7.8) | 2.3% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 25/1/2022 | 17/6/2026 | An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process. | |
| Modificada | Alta (7.8) | 2.9% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 25/1/2022 | 17/6/2026 | A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (8.8) | 54% | — | Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+22 | 18/1/2022 | 17/6/2026 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Media (6.1) | 0.25% | — | Snowsoftware Snow Inventory Agent | 3/11/2021 | 17/6/2026 | A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1 on Windows. | |
| Modificada | Media (6.1) | 41% | 💥 PoC | Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+23 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A… | |
| Modificada | Media (6.1) | 8.5% | — | Jqueryui Jquery UIFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+24 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as… | |
| Modificada | Media (6.1) | 39% | 💥 PoC | Jqueryui Jquery UIFedoraproject FedoraNetapp H500s FirmwareNetapp H700s Firmware+25 | 26/10/2021 | 25/8/2026 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS… | |
| Modificada | Alta (7.5) | 12% | — | Apache TomcatNetapp HCINetapp Management Services FOR Element SoftwareDebian Linux+14 | 14/10/2021 | 17/6/2026 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a… |