Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.64%—Lenovo Xclarity Controller14/2/202017/6/2026
An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is…
ModificadaMedia (5.5)0.74%—Lenovo Xclarity Administrator14/2/202017/6/2026
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
ModificadaAlta (7.5)1.0%—Lenovo Xclarity Administrator14/2/202017/6/2026
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.
ModificadaMedia (5.4)0.52%—Lenovo Xclarity Administrator14/2/202017/6/2026
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code…
ModificadaMedia (6.5)0.86%—Lenovo Xclarity Controller20/11/201917/6/2026
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted…
ModificadaMedia (4.9)0.65%—Lenovo Xclarity Administrator3/9/201917/6/2026
A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on…
ModificadaMedia (6.1)0.82%—Lenovo Xclarity Administrator3/9/201917/6/2026
A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.
ModificadaMedia (4.8)0.65%—Lenovo Xclarity Administrator3/9/201917/6/2026
A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.
ModificadaAlta (7.5)1.4%—Lenovo Xclarity AdministratorLenovo Xclarity Integrator3/9/201917/6/2026
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow…
ModificadaMedia (5.9)1.5%—Lenovo Xclarity Administrator3/5/201917/6/2026
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA versions 2.0.0 to 2.3.x.
ModificadaMedia (6.5)0.86%—Lenovo Xclarity Integrator30/11/201817/6/2026
In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads.
ModificadaMedia (6.5)0.45%—Lenovo Xclarity Integrator30/11/201817/6/2026
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.
ModificadaMedia (6.5)0.73%—Lenovo Xclarity Integrator30/11/201817/6/2026
In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload of a backup file.
ModificadaAlta (8.8)2.2%—Lenovo Xclarity Administrator30/7/201817/6/2026
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.
ModificadaAlta (7.5)0.46%—Lenovo Xclarity Administrator30/7/201817/6/2026
In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those…
ModificadaAlta (8.8)0.96%—Lenovo Xclarity Administrator30/7/201817/6/2026
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.
ModificadaCrítica (9.8)3.8%—OpenslpDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+3423/4/201817/6/2026
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
ModificadaMedia (5.3)0.89%—Lenovo Xclarity Administrator30/11/201717/6/2026
A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.
ModificadaAlta (8.8)1.0%—Lenovo Xclarity Administrator22/9/201717/6/2026
Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.
ModificadaMedia (6.7)0.32%—Lenovo Xclarity Administrator22/9/201717/6/2026
An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2.
ModificadaAlta (7.8)0.40%—Lenovo Xclarity Administrator20/6/201717/6/2026
In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative…
ModificadaCrítica (9.8)1.1%—Lenovo Xclarity Administrator1/3/201717/6/2026
Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.
ModificadaAlta (7)0.30%—Lenovo Xclarity Administrator12/1/201717/6/2026
Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords for internal administrative LXCA accounts with temporary passwords that are…
Orbitaley — Vulnerabilidades