Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.7) | 0.27% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+18 | 8/5/2024 | 17/6/2026 | When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (5) | 0.14% | — | Motorola Services MainAI | 3/5/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. | |
| Aplazada | Alta (7.7) | 0.66% | — | Alfresco Content ServicesAI | 2/5/2024 | 17/6/2026 | An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service. | |
| Aplazada | Media (4.3) | 0.20% | — | Alumnionline WEB Services LLC WP ADA Compliance Check BasicAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AlumniOnline Web Services LLC WP ADA Compliance Check Basic.This issue affects WP ADA Compliance Check Basic: from n/a through 3.1.3. | |
| Modificada | Alta (7.1) | 1.0% | — | Fedoraproject SssdRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64+19 | 18/4/2024 | 17/6/2026 | A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. | |
| Analizada | Media (6.5) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3… | |
| Analizada | Media (6.5) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong… | |
| Analizada | Media (6.5) | 1.0% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch.… | |
| Analizada | Media (5.3) | 1.1% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use… | |
| Analizada | Alta (8.8) | 1.3% | — | Net-snmpFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+11 | 16/4/2024 | 17/6/2026 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users… | |
| Analizada | Alta (8.8) | 0.30% | — | Cisco Identity Services Engine | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the… | |
| Analizada | Media (5.5) | 0.37% | — | Cisco Identity Services Engine | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker… | |
| Aplazada | Alta (7.1) | 0.35% | — | Katz WEB Services INC Contact Form 7 NewsletterAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katz Web Services, Inc. Contact Form 7 Newsletter allows Reflected XSS.This issue affects Contact Form 7 Newsletter: from n/a through 2.2. | |
| Analizada | Alta (8.8) | 0.65% | — | Microsoft Xbox Gaming Services | 21/3/2024 | 17/6/2026 | Xbox Gaming Services Elevation of Privilege Vulnerability | |
| Aplazada | Media (6.3) | 0.20% | — | Fujifilm Centreware Internet ServicesAIFujifilm Internet ServicesAI | 18/3/2024 | 17/6/2026 | Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unauthenticated attacker to alter user information. In the case the user is an administrator, the settings such as the administrator's ID, password, etc. may be altered. As… | |
| Modificada | Media (6.5) | 0.49% | — | Honeywell Masmobile Asp.net ServicesHoneywell Masmobile Classic | 16/3/2024 | 17/6/2026 | Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history. | |
| Modificada | Media (5.5) | 0.17% | — | IBM Host Access Transformation Services | 15/3/2024 | 17/6/2026 | IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 210989. | |
| Aplazada | Media (5) | 0.15% | — | Motorola Carrier ServicesAI | 4/3/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization. | |
| Analizada | Alta (7.5) | 0.55% | — | Common-services SO Flexibilite | 3/3/2024 | 17/6/2026 | An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file. | |
| Analizada | Alta (7.8) | 0.19% | — | Aveva Platform Common Services | 29/2/2024 | 17/6/2026 | The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL. | |
| Modificada | Media (5.5) | 0.44% | — | MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+4 | 29/2/2024 | 17/6/2026 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c. | |
| Analizada | Alta (7.5) | 1.1% | — | MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+5 | 29/2/2024 | 17/6/2026 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. | |
| Analizada | Media (5.3) | 0.81% | — | MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+5 | 29/2/2024 | 17/6/2026 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. | |
| Analizada | Media (5.9) | 0.39% | — | Common-services SO Flexibilite | 27/2/2024 | 17/6/2026 | In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection. |