Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.67% | — | Generalbytes Crypto Application ServerAI | 19/9/2025 | 17/6/2026 | General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 20220725.22 (mainline) contains an authentication bypass in the admin web interface. An unauthenticated attacker could invoke the same URL used by the product's default-installation / first-admin creation… | |
| Analizada | Alta (8.1) | 0.20% | — | General Data Protection Regulation Project General Data Protection Regulation | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2. | |
| Modificada | Crítica (9.8) | 1.1% | — | Maxiguvenlik General Device Manager | 25/9/2023 | 17/6/2026 | General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow. | |
| Modificada | Media (6.1) | 0.41% | — | General-solutions Contwise Case2 | 1/9/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | |
| Modificada | Media (6.1) | 0.41% | — | General-solutions Contwise Case2 | 1/9/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notification.message parameter. | |
| Modificada | Media (6.1) | 0.36% | — | General-solutions Contwise Case2 | 1/9/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tasktyp parameter. | |
| Modificada | Media (6.1) | 0.45% | — | General-solutions Contwise Case2 | 1/9/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the executionBlockName parameter. | |
| Modificada | Media (6.1) | 0.36% | — | General-solutions Contwise Case2 | 1/9/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fieldname parameter. | |
| Modificada | Crítica (9.1) | 21% | — | Generalbytes Crypto Application Server | 22/3/2023 | 17/6/2026 | General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in… | |
| Modificada | Crítica (9.8) | 1.0% | — | Generalized Electric Vehicle Reverse Engineering Tool Project Generalized Electric Vehicle Reverse Engineering Tool | 3/8/2022 | 17/6/2026 | GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp. | |
| Modificada | Media (5.5) | 0.35% | — | Oracle VirtualizationRedhat AnsibleRedhat Ansible TowerRedhat Cisco Nx-os Collection+4 | 26/5/2021 | 17/6/2026 | A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality.… | |
| Modificada | Alta (8.1) | 0.99% | — | Oracle General Ledger | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Account Hierarchy Manager). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful… | |
| Modificada | Media (4.3) | 0.56% | — | SAP S/4 Hana Fiori UI FOR General Ledger Accounting | 12/8/2020 | 17/6/2026 | SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check. | |
| Modificada | Alta (7.5) | 1.7% | — | Oracle General Ledger | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Account Hierarchy Manager). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General… | |
| Modificada | Crítica (9.9) | 1.4% | — | Oracle General Ledger | 23/4/2019 | 17/6/2026 | Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows low privileged attacker with… | |
| Modificada | Alta (8.8) | 1.5% | — | Logological General-purpose Preprocessor | 16/9/2018 | 17/6/2026 | GPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or possibly unspecified other impact via a crafted file. | |
| Modificada | Alta (7.8) | 0.38% | — | IBM General Parallel File SystemIBM Spectrum Scale | 13/6/2018 | 17/6/2026 | A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID:… | |
| Modificada | Alta (7.5) | 1.8% | — | General-file-server Project General-file-server | 7/6/2018 | 17/6/2026 | general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which allows a malicious user to read content of any file with known path. | |
| Modificada | Baja (3.3) | 0.38% | — | IBM Spectrum ScaleIBM General Parallel File System | 2/3/2018 | 17/6/2026 | IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378. | |
| Modificada | Alta (7.5) | 2.6% | — | Oracle General Ledger | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Alta (7.2) | 4.0% | — | IBM General Parallel File SystemIBM Spectrum Scale | 1/2/2017 | 17/6/2026 | IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash. | |
| Modificada | Alta (8.8) | 27% | — | Cisco Activetouch General Plugin ContainerCisco Download ManagerCisco Gpccontainer ClassCisco Webex+2 | 1/2/2017 | 17/6/2026 | An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on… | |
| Modificada | Alta (7) | 0.30% | — | IBM Spectrum ScaleIBM General Parallel File System | 25/11/2016 | 17/6/2026 | IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted environment variables to a /usr/lpp/mmfs/bin/ setuid program. | |
| Modificada | Alta (7) | 0.30% | — | IBM Spectrum ScaleIBM General Parallel File System | 25/11/2016 | 17/6/2026 | IBM Spectrum Scale 4.1.1.x before 4.1.1.8 and 4.2.x before 4.2.0.4 and General Parallel File System (GPFS) 3.5.x before 3.5.0.32 and 4.1.x before 4.1.1.8 allow local users to gain privileges via crafted command-line parameters to a /usr/lpp/mmfs/bin/ setuid program. | |
| Modificada | Media (6.5) | 1.8% | — | IBM General Parallel File System | 8/8/2016 | 17/6/2026 | IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords. |