Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.58% | — | Opennav Nav2Openrobotics Robot Operating System | 20/2/2024 | 17/6/2026 | Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. | |
| Analizada | Crítica (9.1) | 0.71% | — | Opennav Nav2Openrobotics Robot Operating System | 20/2/2024 | 17/6/2026 | Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. | |
| Analizada | Media (6.5) | 0.68% | — | Opennav Nav2Openrobotics Robot Operating System | 20/2/2024 | 17/6/2026 | Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp. | |
| Analizada | Baja (3.3) | 0.29% | — | Opennav Nav2Openrobotics Robot Operating System | 20/2/2024 | 17/6/2026 | Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file. | |
| Analizada | Alta (7.8) | 0.15% | — | Microfocus Operations Agent | 15/2/2024 | 17/6/2026 | Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platforms. The vulnerability could allow local privilege escalation. | |
| Modificada | Media (5.4) | 0.29% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the affected user or carry out any actions that this user could perform, or to generally control the victim's browser. | |
| Modificada | Alta (7.8) | 0.64% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.64% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges. | |
| Modificada | Media (6.5) | 0.35% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain unauthorized write access to the files stored on the server filesystem, with elevated privileges. | |
| Modificada | Alta (7.8) | 1.0% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.88% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 0.88% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the… | |
| Modificada | Alta (7.8) | 0.90% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of… | |
| Modificada | Media (6.5) | 0.42% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information. | |
| Modificada | Alta (7.8) | 0.84% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges. | |
| Modificada | Media (5.4) | 0.32% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Modificada | Alta (7.8) | 0.84% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands… | |
| Modificada | Alta (7.8) | 0.81% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges. | |
| Modificada | Alta (7.8) | 1.1% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges. | |
| Modificada | Alta (7.8) | 0.95% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges. | |
| Modificada | Alta (7.8) | 1.1% | — | Dell Unity Operating Environment | 12/2/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges. | |
| Modificada | Media (5.4) | 0.31% | — | Wpoperation Ultra Companion | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPoperation Ultra Companion – Companion plugin for WPoperation Themes allows Stored XSS.This issue affects Ultra Companion – Companion plugin for WPoperation Themes: from n/a through 1.1.9. | |
| Modificada | Media (4.8) | 38% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account. | |
| Modificada | Media (4.9) | 0.61% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information. | |
| Modificada | Alta (7.8) | 0.21% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access. |