Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.
AnalizadaMedia (6.9)0.84%—Growatt Cloud Portal15/4/202517/6/2026
An attacker can change registered email addresses of other users and take over arbitrary accounts.
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.
AnalizadaMedia (6.9)0.49%—Growatt Cloud Portal15/4/202517/6/2026
An unauthenticated attacker can infer the existence of usernames in the system by querying an API.
ModificadaMedia (4.3)2.8%—Cisco Cloud Portal30/8/201417/6/2026
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh84801.
ModificadaMedia (5)2.9%—Cisco Cloud Portal29/8/201417/6/2026
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, aka Bug IDs CSCuh87398 and CSCuh87380.
ModificadaMedia (4)1.6%—Cisco Cloud Portal29/8/201417/6/2026
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCuh84870.
ModificadaMedia (4)1.6%—Cisco Cloud Portal29/8/201417/6/2026
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file submission, which allows remote authenticated users to upload arbitrary files via a crafted request, aka Bug ID CSCuh87410.
ModificadaMedia (4)1.6%—Cisco Cloud Portal2/7/201417/6/2026
Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML source code, aka Bug ID CSCui36976.
ModificadaMedia (4)1.8%—Cisco Cloud Portal2/7/201417/6/2026
Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug IDs CSCui36937,…
ModificadaMedia (5)1.2%—Cisco Cloud Portal14/3/201417/6/2026
Intelligent Automation for Cloud (IAC) in Cisco Cloud Portal 9.4.1 and earlier includes a cryptographic key in binary files, which makes it easier for remote attackers to obtain cleartext data from an arbitrary IAC installation by leveraging knowledge of this key, aka Bug IDs CSCui34764, CSCui34772, CSCui34776,…
ModificadaMedia (5)3.0%—Cisco Cloud Portal10/12/201317/6/2026
Cisco Cloud Portal 9.4 allows remote attackers to read files of unspecified types via a direct request, aka Bug IDs CSCuj08426 and CSCui60889.
ModificadaMedia (4)0.94%—Cisco Cloud Portal27/2/201316/6/2026
The nsAPI interface in Cisco Cloud Portal 9.1 SP1 and SP2, and 9.3 through 9.3.2, does not properly check privileges, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCud81134.
Orbitaley — Vulnerabilidades