Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.65% | 💥 PoC | Hsclabs Mailinspector | 6/5/2024 | 17/6/2026 | An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to… | |
| Analizada | Alta (8.6) | 6.7% | 💥 Exploit | Hsclabs Mailinspector | 6/5/2024 | 17/6/2026 | An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the… | |
| Aplazada | Media (4.7) | 0.21% | — | Openstack IronicAIOpenstack Ironic InspectorAI | 17/4/2024 | 17/6/2026 | Ironic-image is an OpenStack Ironic deployment packaged and configured by Metal3. When the reverse proxy mode is enabled by the `IRONIC_REVERSE_PROXY_SETUP` variable set to `true`, 1) HTTP basic credentials are validated on the HTTPD side in a separate container, not in the Ironic service itself and 2) Ironic listens… | |
| Analizada | Alta (7.8) | 0.16% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6) | 0.17% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.23% | — | Cals-ed Electronic Delivery Check SystemCals-ed Electronic Delivery Item Inspection Support System | 24/1/2024 | 17/6/2026 | Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity… | |
| Modificada | Media (6.8) | 0.38% | — | Intel AdvisorIntel InspectorIntel MPI LibraryIntel Oneapi Base Toolkit+1 | 14/11/2023 | 17/6/2026 | Protection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a privileged user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Alta (7.8) | 0.25% | — | Intel AdvisorIntel InspectorIntel MPI LibraryIntel Oneapi Base Toolkit+1 | 14/11/2023 | 17/6/2026 | Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.28% | — | Chef Inspec | 31/10/2023 | 17/6/2026 | Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.44% | — | Jenkins Security Inspector | 21/9/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier allows attackers to replace the generated report stored in a per-session cache and displayed to authorized users at the .../report URL with a report based on attacker-specified report generation options. | |
| Modificada | Alta (7.5) | 2.1% | — | Schema-inspector Project Schema-inspectorNetapp E-series Performance AnalyzerNetapp Oncommand Insight | 19/3/2021 | 17/6/2026 | Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example… | |
| Modificada | Media (5.5) | 0.62% | — | Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+15 | 3/3/2021 | 17/6/2026 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | |
| Modificada | Alta (7.8) | 1.3% | — | Emerson Rosemount Transmitter Interface SoftwarePepperl-fuchs PactwareWago Dtminspector 3Wago Fdtcontainer Application+3 | 22/1/2021 | 17/6/2026 | M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. | |
| Modificada | Crítica (9.6) | 10% | — | Microsoft Application Inspector | 12/3/2020 | 17/6/2026 | A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Apache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+17 | 24/2/2020 | 25/8/2026 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.… | |
| Modificada | Media (4.8) | 9.4% | — | Apache TomcatDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+16 | 24/2/2020 | 17/6/2026 | In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly… | |
| Modificada | Media (4.8) | 8.9% | — | Apache TomcatApache TomeeOpensuse LeapNetapp Data Availability Services+12 | 24/2/2020 | 25/8/2026 | The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy… | |
| Modificada | Crítica (9.8) | 1.4% | — | Schema-inspector Project Schema-inspector | 22/1/2020 | 17/6/2026 | In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector. | |
| Modificada | Crítica (9.8) | 2.8% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attacker's cloud endpoint. | |
| Modificada | Alta (7.5) | 0.84% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being stored in cleartext in device configuration. | |
| Modificada | Alta (7.5) | 1.1% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing. | |
| Modificada | Media (5.3) | 1.0% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances of Zingbox Inspectors in a local area network. |