Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Netapp Cloud Manager | 19/3/2021 | 17/6/2026 | Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a Denial of Service (DoS). | |
| Modificada | Alta (7.5) | 1.2% | — | Netapp Cloud Manager | 19/3/2021 | 17/6/2026 | Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow a remote attacker to interact with Cloud Manager. | |
| Modificada | Crítica (9.1) | 1.5% | — | Netapp Cloud Manager | 19/3/2021 | 17/6/2026 | Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite arbitrary system files. | |
| Modificada | Alta (8.6) | 7.3% | — | Squid-cache SquidDebian LinuxFedoraproject FedoraNetapp Cloud Manager | 19/3/2021 | 17/6/2026 | An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings. | |
| Modificada | Alta (7.2) | 21% | — | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+19 | 15/2/2021 | 17/6/2026 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | |
| Modificada | Alta (7.5) | 2.5% | — | Squid-cache SquidFedoraproject FedoraNetapp Cloud Manager | 30/6/2020 | 17/6/2026 | An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a TLS connection to an attacker-controlled server for HTTPS. This occurs because unrecognized error… | |
| Modificada | Crítica (9.8) | 2.8% | — | Netapp Oncommand Cloud Manager | 26/2/2020 | 17/6/2026 | OnCommand Cloud Manager versions prior to 3.8.0 are susceptible to arbitrary code execution by remote attackers. | |
| Modificada | Media (4.4) | 0.38% | — | IBM Multicloud Manager | 11/7/2019 | 17/6/2026 | IBM Multicloud Manager 3.1.0, 3.1.1, and 3.1.2 ibm-mcm-chart could allow a local attacker with admin privileges to obtain highly sensitive information upon deployment. IBM X-Force ID: 158144. | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Oracle JDKOracle JREOracle JrockitOracle Linux+34 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | |
| Modificada | Media (5.4) | 0.27% | — | Cubettechnologies Cloud Manager | 9/9/2014 | 17/6/2026 | The Cloud Manager (aka com.ileaf.cloud_manager) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 3.6% | — | Novell Cloud Manager | 6/9/2011 | 16/6/2026 | The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session. |