Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.77%—Cisco Prime Collaboration Provisioning2/9/202117/6/2026
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based…
ModificadaAlta (7.1)1.4%💥 PoCMicrosoft Azure Active Directory ConnectMicrosoft Azure Active Directory Connect Provisioning Agent12/8/202110/8/2026
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
ModificadaMedia (4.4)1.2%💥 ExploitAkkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager22/7/202117/6/2026
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning…
ModificadaCrítica (9.8)3.0%—Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager22/7/202117/6/2026
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2…
ModificadaCrítica (9.8)1.3%—Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager22/7/202117/6/2026
Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).
ModificadaAlta (8.8)1.3%—Akkadianlabs Akkadian Provisioning Manager1/7/202117/6/2026
An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges.
ModificadaAlta (7.5)6.8%💥 ExploitAkkadianlabs Akkadian Provisioning Manager1/7/202117/6/2026
An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.
ModificadaAlta (8.8)1.2%—SAP Software Provisioning Manager9/2/202117/6/2026
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade.
ModificadaCrítica (9.8)12%—HP Moonshot Provisioning Manager9/2/202117/6/2026
A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be…
ModificadaCrítica (9.8)7.9%—HP Moonshot Provisioning Manager9/2/202117/6/2026
A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be…
ModificadaMedia (6.7)0.42%—HPE Intelligent ProvisioningHPE Service Pack FOR ProliantHPE Smartstart Scripting Toolkit30/7/202017/6/2026
A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot process. **Note:** This vulnerability is related to using insmod in GRUB2 in the…
ModificadaMedia (6.5)0.97%—Oracle Financial Services Loan Loss Forecasting AND Provisioning15/7/202017/6/2026
Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6-8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaAlta (7.2)0.94%—Cisco Prime Collaboration Provisioning22/5/202017/6/2026
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates user input for specific…
ModificadaMedia (6.1)99%💥 ExploitJqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaAlta (7.1)1.1%—Oracle Financial Services Loan Loss Forecasting AND Provisioning15/4/202017/6/2026
Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…
ModificadaMedia (5.3)1.1%—Cisco Prime Collaboration Provisioning4/3/202017/6/2026
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to obtain sensitive information about an affected device. The vulnerability exists because replies from the web-based management interface include unnecessary server…
ModificadaMedia (6.1)0.80%—Cisco Prime Collaboration Provisioning4/3/202017/6/2026
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input…
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaMedia (5.5)0.73%—HP Moonshot Provisioning ManagerCanonical Ubuntu Linux6/8/201817/6/2026
A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
ModificadaCrítica (9.8)3.1%—HP Moonshot Provisioning Manager6/8/201817/6/2026
A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
ModificadaMedia (6.5)2.7%—Cisco Prime CollaborationCisco Prime Collaboration Provisioning1/8/201817/6/2026
A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient validation of a password change request. An attacker could exploit this vulnerability by changing a…
ModificadaAlta (8.8)2.6%—Cisco Prime CollaborationCisco Prime Collaboration Provisioning7/6/201817/6/2026
A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vulnerability is due to a failure to enforce access restrictions on the Help Desk…
ModificadaCrítica (9.8)3.6%—Cisco Prime CollaborationCisco Prime Collaboration AssuranceCisco Prime Collaboration Provisioning7/6/201817/6/2026
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invocation (RMI) system. The vulnerability is due to an open port in the Network Interface and Configuration Engine (NICE) service. An attacker could exploit this…
ModificadaCrítica (9.8)4.0%—Cisco Prime CollaborationCisco Prime Collaboration Provisioning7/6/201817/6/2026
A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by…
ModificadaCrítica (9.8)3.1%—Cisco Prime CollaborationCisco Prime Collaboration Provisioning7/6/201817/6/2026
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of a password recovery request. An attacker could exploit this…
Orbitaley — Vulnerabilidades