Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
130 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.14% | — | Lenovo Dolby Vision Provisioning | 11/10/2024 | 17/6/2026 | A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by… | |
| Analizada | Media (6.9) | 32% | 💥 Exploit | Provision-isr Sh-4050a5-5l(mm) FirmwareTVT Avision Av108t FirmwareTVT Td-2104ts-cl FirmwareTVT Td-2108ts-hp Firmware | 1/8/2024 | 17/6/2026 | A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely.… | |
| Analizada | Alta (7.8) | 0.26% | — | Canonical Ubuntu Desktop Provision | 23/7/2024 | 17/6/2026 | An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege. | |
| Analizada | Media (4.8) | 0.24% | — | Citrix Provisioning | 10/7/2024 | 17/6/2026 | A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Server Debug AND Provisioning Tool | 11/8/2023 | 17/6/2026 | Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.16% | — | HPE Intelligent Provisioning | 18/7/2023 | 17/6/2026 | The vulnerability could be locally exploited to allow escalation of privilege. | |
| Modificada | Alta (7.5) | 0.54% | — | Intel Server Debug AND Provisioning Tool | 11/11/2022 | 17/6/2026 | Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Prime Collaboration Provisioning | 2/9/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based… | |
| Modificada | Alta (7.1) | 1.4% | 💥 PoC | Microsoft Azure Active Directory ConnectMicrosoft Azure Active Directory Connect Provisioning Agent | 12/8/2021 | 10/8/2026 | Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | |
| Modificada | Media (4.4) | 1.2% | 💥 Exploit | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning… | |
| Modificada | Crítica (9.8) | 3.0% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2… | |
| Modificada | Crítica (9.8) | 1.3% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later). | |
| Modificada | Alta (8.8) | 1.3% | — | Akkadianlabs Akkadian Provisioning Manager | 1/7/2021 | 17/6/2026 | An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges. | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Akkadianlabs Akkadian Provisioning Manager | 1/7/2021 | 17/6/2026 | An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories. | |
| Modificada | Alta (8.8) | 1.2% | — | SAP Software Provisioning Manager | 9/2/2021 | 17/6/2026 | SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade. | |
| Modificada | Crítica (9.8) | 12% | — | HP Moonshot Provisioning Manager | 9/2/2021 | 17/6/2026 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be… | |
| Modificada | Crítica (9.8) | 7.9% | — | HP Moonshot Provisioning Manager | 9/2/2021 | 17/6/2026 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be… | |
| Modificada | Media (6.7) | 0.42% | — | HPE Intelligent ProvisioningHPE Service Pack FOR ProliantHPE Smartstart Scripting Toolkit | 30/7/2020 | 17/6/2026 | A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the… | |
| Modificada | Media (6.5) | 0.97% | — | Oracle Financial Services Loan Loss Forecasting AND Provisioning | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6-8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Alta (7.2) | 0.94% | — | Cisco Prime Collaboration Provisioning | 22/5/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates user input for specific… | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (7.1) | 1.1% | — | Oracle Financial Services Loan Loss Forecasting AND Provisioning | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… |