Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.77% | — | Cisco Prime Collaboration Provisioning | 2/9/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based… | |
| Modificada | Alta (7.1) | 1.4% | 💥 PoC | Microsoft Azure Active Directory ConnectMicrosoft Azure Active Directory Connect Provisioning Agent | 12/8/2021 | 10/8/2026 | Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | |
| Modificada | Media (4.4) | 1.2% | 💥 Exploit | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning… | |
| Modificada | Crítica (9.8) | 3.0% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2… | |
| Modificada | Crítica (9.8) | 1.3% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later). | |
| Modificada | Alta (8.8) | 1.3% | — | Akkadianlabs Akkadian Provisioning Manager | 1/7/2021 | 17/6/2026 | An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges. | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Akkadianlabs Akkadian Provisioning Manager | 1/7/2021 | 17/6/2026 | An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories. | |
| Modificada | Alta (8.8) | 1.2% | — | SAP Software Provisioning Manager | 9/2/2021 | 17/6/2026 | SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade. | |
| Modificada | Crítica (9.8) | 12% | — | HP Moonshot Provisioning Manager | 9/2/2021 | 17/6/2026 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be… | |
| Modificada | Crítica (9.8) | 7.9% | — | HP Moonshot Provisioning Manager | 9/2/2021 | 17/6/2026 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be… | |
| Modificada | Media (6.7) | 0.42% | — | HPE Intelligent ProvisioningHPE Service Pack FOR ProliantHPE Smartstart Scripting Toolkit | 30/7/2020 | 17/6/2026 | A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the… | |
| Modificada | Media (6.5) | 0.97% | — | Oracle Financial Services Loan Loss Forecasting AND Provisioning | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6-8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Alta (7.2) | 0.94% | — | Cisco Prime Collaboration Provisioning | 22/5/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates user input for specific… | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | JqueryDrupalDebian LinuxFedoraproject Fedora+66 | 29/4/2020 | 17/6/2026 | In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (7.1) | 1.1% | — | Oracle Financial Services Loan Loss Forecasting AND Provisioning | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (5.3) | 1.1% | — | Cisco Prime Collaboration Provisioning | 4/3/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server… | |
| Modificada | Media (6.1) | 0.80% | — | Cisco Prime Collaboration Provisioning | 4/3/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input… | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Media (5.5) | 0.73% | — | HP Moonshot Provisioning ManagerCanonical Ubuntu Linux | 6/8/2018 | 17/6/2026 | A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. | |
| Modificada | Crítica (9.8) | 3.1% | — | HP Moonshot Provisioning Manager | 6/8/2018 | 17/6/2026 | A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. | |
| Modificada | Media (6.5) | 2.7% | — | Cisco Prime CollaborationCisco Prime Collaboration Provisioning | 1/8/2018 | 17/6/2026 | A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient validation of a password change request. An attacker could exploit this vulnerability by changing a… | |
| Modificada | Alta (8.8) | 2.6% | — | Cisco Prime CollaborationCisco Prime Collaboration Provisioning | 7/6/2018 | 17/6/2026 | A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vulnerability is due to a failure to enforce access restrictions on the Help Desk… | |
| Modificada | Crítica (9.8) | 3.6% | — | Cisco Prime CollaborationCisco Prime Collaboration AssuranceCisco Prime Collaboration Provisioning | 7/6/2018 | 17/6/2026 | A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this… | |
| Modificada | Crítica (9.8) | 4.0% | — | Cisco Prime CollaborationCisco Prime Collaboration Provisioning | 7/6/2018 | 17/6/2026 | A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.8) | 3.1% | — | Cisco Prime CollaborationCisco Prime Collaboration Provisioning | 7/6/2018 | 17/6/2026 | A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password recovery request. An attacker could exploit this… |