Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)5.7%—Apache Velocity ToolsDebian Linux10/3/202117/6/2026
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vulnerabilities allow attackers to execute arbitrary…
ModificadaAlta (8.8)23%—Apache Velocity EngineApache Wss4jDebian LinuxOracle Banking Deposits AND Lines OF Credit Servicing+1210/3/202117/6/2026
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine…
ModificadaMedia (6.1)0.67%—Iteris Vantage Velocity Firmware17/2/202017/6/2026
Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.
ModificadaCrítica (9.8)1.8%—Iteris Vantage Velocity Firmware17/2/202017/6/2026
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.
ModificadaCrítica (9.8)1.5%—Iteris Vantage Velocity Firmware17/2/202017/6/2026
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.
ModificadaCrítica (9.8)2.5%—Iteris Vantage Velocity Firmware17/2/202017/6/2026
Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.
ModificadaMedia (4.3)1.2%—Fastvelocity Minify26/12/201917/6/2026
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.
ModificadaAlta (10)31%💥 ExploitThomsonreuters Velocity Analytics Vhayu Analytic Server28/11/201316/6/2026
VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action.
ModificadaMedia (5)2.8%💥 ExploitHirschelectronics Velocity Security Management System26/8/200916/6/2026
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaAlta (10)2.2%—Cisco Application Velocity System23/1/200816/6/2026
Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges.
ModificadaMedia (6.4)1.5%—Cisco Application Velocity System 3110Cisco Application Velocity System 312012/5/200616/6/2026
The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to proxy arbitrary TCP connections, aka Bug ID CSCsd32143.
Orbitaley — Vulnerabilidades