Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.80% | — | Presscustomizr Nimble Page Builder | 11/4/2022 | 17/6/2026 | The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (7.2) | 1.5% | — | Nimble3 M-vslider | 23/8/2021 | 17/6/2026 | The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role. | |
| Modificada | Media (6.5) | 1.1% | — | Nimble-project Common | 26/7/2021 | 17/6/2026 | Common is a package of common modules that can be accessed by NIMBLE services. Common before commit number 3b96cb0293d3443b870351945f41d7d55cb34b53 did not properly verify the signature of JSON Web Tokens. This allows someone to forge a valid JWT. Being able to forge JWTs may lead to authentication bypasses. Commit… | |
| Modificada | Alta (8.1) | 0.88% | — | HPE Nimbleos | 19/5/2020 | 17/6/2026 | Potential remote access security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to access and modify sensitive information on the system. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.3.0… | |
| Modificada | Alta (8.8) | 1.8% | — | HPE Nimbleos | 19/5/2020 | 17/6/2026 | Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.3.0 4.5.6.0… | |
| Modificada | Crítica (9.8) | 1.5% | — | HPE Nimbleos | 7/11/2019 | 17/6/2026 | Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this… | |
| Modificada | Media (6.5) | 27% | 💥 Exploit | Softvelum Nimble Streamer | 22/8/2019 | 17/6/2026 | Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server. | |
| Modificada | Alta (8.8) | 0.91% | — | Ranksol Nimble Professional | 19/6/2019 | 17/6/2026 | CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account. |