Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.66%—Sonarsource Sonarqube14/10/201917/6/2026
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
ModificadaMedia (6.1)0.69%—Xerox Colorqube 8580 Firmware13/5/201917/6/2026
Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
ModificadaCrítica (9.8)8.5%—Xerox Colorqube 8700 FirmwareXerox Colorqube 8900 FirmwareXerox Colorqube 9301 FirmwareXerox Colorqube 9302 Firmware+112/4/201917/6/2026
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
ModificadaAlta (7.8)0.34%—Sonarsource Sonarqube Scanner9/1/201917/6/2026
An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube.
ModificadaMedia (4.3)1.1%—Sonarsource Sonarqube14/12/201817/6/2026
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field…
ModificadaCrítica (9.8)2.4%—Iceqube Thermal Management Center Firmware6/9/201817/6/2026
In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authentication.
ModificadaAlta (7.5)1.8%—Iceqube Thermal Management Center Firmware6/9/201817/6/2026
In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allow an attacker to gain access to sensitive information.
ModificadaAlta (10)4.4%💥 ExploitCobalt Qube4/10/200216/6/2026
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.
ModificadaMedia (5)8.1%💥 ExploitCobalt QubeCobalt Webmail5/7/200116/6/2026
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter.
ModificadaMedia (5)1.4%—Cobalt QubeSUN Cobalt RAQSUN Cobalt RAQ 2SUN Cobalt RAQ 3I+219/11/199916/6/2026
Denial of service in Linux syslogd via a large number of connections.