Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 2.7% | — | Cisco DNA Spaces\ | 22/5/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these… | |
| Modificada | Alta (7.2) | 2.7% | — | Cisco DNA Spaces\ | 22/5/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these… | |
| Modificada | Media (6.7) | 0.33% | — | Cisco DNA Spaces\ | 22/5/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions during the execution of affected CLI commands. An attacker… | |
| Modificada | Media (6.7) | 0.33% | — | Cisco DNA Spaces\ | 22/5/2021 | 17/6/2026 | Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions during the execution of affected CLI commands. An attacker… | |
| Modificada | Alta (8.8) | 0.96% | — | Blackberry Workspaces Server | 13/5/2021 | 17/6/2026 | An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10.1, 9.1 and earlier could allow an attacker to potentially gain access to the application in the context of the targeted user’s account. | |
| Modificada | Alta (8.8) | 0.22% | — | Tibco Activespaces | 23/3/2021 | 17/6/2026 | The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows… | |
| Modificada | Crítica (9.8) | 2.5% | — | Cisco DNA Spaces\ | 18/11/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied input in the web-based management interface. An attacker could… | |
| Analizada | Media (6.5) | 86% | ⚠ Explotación activa | Saltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2 | 30/4/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Apache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+17 | 24/2/2020 | 25/8/2026 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.… | |
| Modificada | Media (6.7) | 0.73% | — | Cisco DNA Spaces\ | 26/11/2019 | 17/6/2026 | A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient validation of arguments passed to a specific CLI command. An attacker… | |
| Modificada | Media (6.7) | 0.52% | — | Cisco DNA Spaces\ | 26/11/2019 | 17/6/2026 | A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restrictions during the execution of an affected CLI command. An attacker could exploit… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco DNA Spaces\ | 26/11/2019 | 17/6/2026 | A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by entering malicious SQL statements in… | |
| Modificada | Alta (8.8) | 0.87% | — | Tibco Activespaces | 6/11/2018 | 17/6/2026 | The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are… | |
| Modificada | Alta (7.5) | 1.4% | — | Blackberry Workspaces VappBlackberry Workspaces Appliance-x | 16/10/2017 | 17/6/2026 | An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files. | |
| Modificada | Crítica (9.8) | 1.6% | — | Blackberry Workspaces VappBlackberry Workspaces Appliance-x | 16/10/2017 | 17/6/2026 | A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request. | |
| Modificada | Alta (8.8) | 0.86% | — | Blackberry Workspaces | 9/8/2017 | 17/6/2026 | An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server. | |
| Modificada | Media (6.1) | 0.95% | — | Blackberry Appliance-xBlackberry Workspaces Vapp | 13/1/2017 | 17/6/2026 | A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious… | |
| Modificada | Baja (2.1) | 0.95% | — | Florian Weber Spaces | 17/5/2014 | 16/6/2026 | The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain… | |
| Modificada | Alta (7.5) | 2.0% | — | Florian Weber Spaces | 18/7/2012 | 16/6/2026 | The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module. | |
| Modificada | Alta (7.5) | 1.0% | — | Astrospaces | 21/10/2008 | 16/6/2026 | SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action. |