Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.66% | — | Sonarsource Sonarqube | 14/10/2019 | 17/6/2026 | SonarSource SonarQube before 7.8 has XSS in project links on account/projects. | |
| Modificada | Media (6.1) | 0.69% | — | Xerox Colorqube 8580 Firmware | 13/5/2019 | 17/6/2026 | Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code. | |
| Modificada | Crítica (9.8) | 8.5% | — | Xerox Colorqube 8700 FirmwareXerox Colorqube 8900 FirmwareXerox Colorqube 9301 FirmwareXerox Colorqube 9302 Firmware+1 | 12/4/2019 | 17/6/2026 | Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary. | |
| Modificada | Alta (7.8) | 0.34% | — | Sonarsource Sonarqube Scanner | 9/1/2019 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube. | |
| Modificada | Media (4.3) | 1.1% | — | Sonarsource Sonarqube | 14/12/2018 | 17/6/2026 | A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field… | |
| Modificada | Crítica (9.8) | 2.4% | — | Iceqube Thermal Management Center Firmware | 6/9/2018 | 17/6/2026 | In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authentication. | |
| Modificada | Alta (7.5) | 1.8% | — | Iceqube Thermal Management Center Firmware | 6/9/2018 | 17/6/2026 | In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allow an attacker to gain access to sensitive information. | |
| Modificada | Alta (10) | 4.4% | 💥 Exploit | Cobalt Qube | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Cobalt QubeCobalt Webmail | 5/7/2001 | 16/6/2026 | Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter. | |
| Modificada | Media (5) | 1.4% | — | Cobalt QubeSUN Cobalt RAQSUN Cobalt RAQ 2SUN Cobalt RAQ 3I+2 | 19/11/1999 | 16/6/2026 | Denial of service in Linux syslogd via a large number of connections. |