Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.33% | — | Opentext Operations Bridge ManagerAIOpentext Operations Bridge SuiteAIOpentext UcmdbAI | 17/4/2025 | 17/6/2026 | Incorrect Use of Privileged APIs vulnerability in OpenText™ Operations Bridge Manager, OpenText™ Operations Bridge Suite (Containerized), OpenText™ UCMDB ( Classic and Containerized) allows Privilege Escalation. The vulnerability could allow authenticated attackers to elevate user privileges. This issue affects… | |
| Analizada | Alta (7.8) | 0.88% | — | Microsoft System Center Data Protection ManagerMicrosoft System Center Operations ManagerMicrosoft System Center OrchestratorMicrosoft System Center Service Manager+1 | 8/4/2025 | 17/6/2026 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.5) | 0.36% | — | Wpoperations Wpop-elementor-addonsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpoperations WPoperation Elementor Addons wpop-elementor-addons allows Stored XSS.This issue affects WPoperation Elementor Addons: from n/a through <= 1.1.9. | |
| Aplazada | Alta (7.8) | 0.15% | — | Vmware Aria OperationsAI | 1/4/2025 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations. | |
| Aplazada | Media (5.3) | 0.31% | — | Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management AND Operations SystemAI | 1/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this issue is some unknown functionality of the file /wuser/anyUserBoundHouse.php. The manipulation of the argument huid leads to… | |
| Analizada | Alta (7.5) | 0.66% | — | Audiocodes ONE Voice Operations Center | 7/2/2025 | 17/6/2026 | An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication. | |
| Analizada | Media (6.1) | 0.24% | — | Audiocodes ONE Voice Operations Center | 7/2/2025 | 17/6/2026 | An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions. | |
| Analizada | Alta (7.5) | 0.36% | — | Audiocodes ONE Voice Operations Center | 7/2/2025 | 17/6/2026 | An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file. | |
| Aplazada | Alta (7.1) | 0.13% | — | Operationsissuu Issuu PanelAI | 31/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in operationsissuu Issuu Panel issuu-panel allows Stored XSS.This issue affects Issuu Panel: from n/a through <= 2.1.1. | |
| Analizada | Media (6.5) | 0.56% | — | Vmware Aria OperationsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. | |
| Analizada | Media (4.8) | 0.40% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration. | |
| Analizada | Media (5.4) | 0.33% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user. | |
| Analizada | Crítica (9) | 0.67% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user. | |
| Analizada | Alta (7.7) | 0.68% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 30/1/2025 | 17/6/2026 | VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs | |
| Aplazada | Media (5.3) | 0.50% | — | Opentext Operations Bridge ManagerAI | 19/12/2024 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation. The vulnerability could be exploited to confidential information This issue affects Operations Bridge Manager: 2017.05, 2017.11, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05,… | |
| Analizada | Media (4.8) | 0.31% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Media (5.4) | 0.40% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Media (6.4) | 0.44% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations. | |
| Analizada | Alta (7.8) | 0.29% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running VMware Aria Operations. | |
| Analizada | Alta (7.8) | 0.18% | — | Vmware Aria OperationsVmware Cloud Foundation | 26/11/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations. | |
| Analizada | Baja (1.8) | 0.19% | — | Microfocus Operations Agent | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent. The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the Agent on the local system. This issue affects… | |
| Aplazada | Alta (7.2) | 0.43% | — | Opentext Operations Bridge ReporterAI | 17/5/2024 | 17/6/2026 | A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application. | |
| Analizada | Media (6.2) | 0.89% | — | Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+3 | 9/4/2024 | 17/6/2026 | Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | |
| Aplazada | Alta (7.5) | 0.61% | — | ABB Symphony Plus S+ OperationsAIABB Symphony Plus S+ EngineeringAIABB Symphony Plus S+ AnalystAI | 3/4/2024 | 17/6/2026 | ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3,… | |
| Analizada | Crítica (9.8) | 20% | — | Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |