Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 5.7% | — | Apache Velocity ToolsDebian Linux | 10/3/2021 | 17/6/2026 | The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vulnerabilities allow attackers to execute arbitrary… | |
| Modificada | Alta (8.8) | 23% | — | Apache Velocity EngineApache Wss4jDebian LinuxOracle Banking Deposits AND Lines OF Credit Servicing+12 | 10/3/2021 | 17/6/2026 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine… | |
| Modificada | Media (6.1) | 0.67% | — | Iteris Vantage Velocity Firmware | 17/2/2020 | 17/6/2026 | Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script. | |
| Modificada | Crítica (9.8) | 1.8% | — | Iteris Vantage Velocity Firmware | 17/2/2020 | 17/6/2026 | Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts. | |
| Modificada | Crítica (9.8) | 1.5% | — | Iteris Vantage Velocity Firmware | 17/2/2020 | 17/6/2026 | Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password. | |
| Modificada | Crítica (9.8) | 2.5% | — | Iteris Vantage Velocity Firmware | 17/2/2020 | 17/6/2026 | Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field. | |
| Modificada | Media (4.3) | 1.2% | — | Fastvelocity Minify | 26/12/2019 | 17/6/2026 | In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action. | |
| Modificada | Alta (10) | 31% | 💥 Exploit | Thomsonreuters Velocity Analytics Vhayu Analytic Server | 28/11/2013 | 16/6/2026 | VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Hirschelectronics Velocity Security Management System | 26/8/2009 | 16/6/2026 | Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Alta (10) | 2.2% | — | Cisco Application Velocity System | 23/1/2008 | 16/6/2026 | Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges. | |
| Modificada | Media (6.4) | 1.5% | — | Cisco Application Velocity System 3110Cisco Application Velocity System 3120 | 12/5/2006 | 16/6/2026 | The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to proxy arbitrary TCP connections, aka Bug ID CSCsd32143. |