Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

99 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.4%—Dell Recoverpoint FOR Virtual Machines16/2/202417/6/2026
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete…
AnalizadaCrítica (9.8)0.46%—Dell Recoverpoint FOR Virtual Machines16/2/202417/6/2026
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint login form. This allows attackers to…
ModificadaMedia (6.5)0.64%—Vmware Isolation SegmentVmware Tanzu Application Service FOR Virtual Machines26/7/202317/6/2026
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials…
ModificadaMedia (4.3)0.56%—Oracle Java Virtual Machine18/1/202317/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability…
ModificadaMedia (4.3)0.50%—Oracle Java Virtual Machine18/10/202217/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability…
ModificadaAlta (7.1)0.90%—Oracle Java Virtual Machine20/10/202117/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks…
ModificadaMedia (4.3)0.84%—Oracle Java Virtual Machine21/7/202117/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this…
ModificadaBaja (3.1)0.75%—Oracle Java Virtual Machine21/10/202017/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via multiple protocols to compromise Java VM.…
ModificadaMedia (5.7)0.71%—Vmware Tanzu Application Service FOR Virtual MachinesVmware Operations Manager31/7/202017/6/2026
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the unredacted logs are available to…
ModificadaAlta (8.8)1.9%—Vmware GemfireVmware Tanzu Gemfire FOR Virtual Machines31/7/202017/6/2026
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a malicious user to create an MLet mbean leading…
ModificadaCrítica (9.1)1.8%—Vmware GemfireVmware Tanzu Gemfire FOR Virtual Machines31/7/202017/6/2026
VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may request against the service with a…
ModificadaCrítica (9.8)1.7%—Facebook Hiphop Virtual Machine18/7/201917/6/2026
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would attempt to verify it by re-running…
ModificadaMedia (6.7)0.66%—Dell EMC RecoverpointDell Recoverpoint FOR Virtual Machines15/5/201917/6/2026
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI. A malicious boxmgmt user may potentially be able to execute arbitrary commands as root.
ModificadaAlta (7.1)0.41%—Dell EMC RecoverpointDell EMC Recoverpoint FOR Virtual Machines13/11/201817/6/2026
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulnerability. A malicious boxmgmt user may potentially be able to consume large amount of CPU bandwidth to make the system slow or to determine the existence of any system…
ModificadaMedia (5.5)0.42%—EMC RecoverpointEMC Recoverpoint FOR Virtual Machines13/11/201817/6/2026
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A malicious boxmgmt user may potentially be able to determine the existence of any system file via Boxmgmt CLI.
ModificadaAlta (8.8)1.6%—Webassembly Virtual Machine Project Webassembly Virtual Machine21/9/201817/6/2026
An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input WebAssembly file's main function, which allows attackers to cause a denial of service (application crash by NULL…
ModificadaMedia (6.5)1.2%—Webassembly Virtual Machine Project Webassembly Virtual Machine21/9/201817/6/2026
An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file magic comparison, allowing attackers to cause a Denial of Service (application crash caused by out-of-bounds read) by crafting a file that has fewer than 4 bytes.
ModificadaAlta (8.8)1.3%—Webassembly Virtual Machine Project Webassembly Virtual Machine10/9/201817/6/2026
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because a certain new_allocator allocate call fails.
ModificadaAlta (8.8)1.3%—Webassembly Virtual Machine Project Webassembly Virtual Machine10/9/201817/6/2026
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because libRuntime.so!llvm::InstructionCombiningPass::runOnFunction is mishandled.
ModificadaAlta (8.8)1.3%—Webassembly Virtual Machine Project Webassembly Virtual Machine10/9/201817/6/2026
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in IR::FunctionValidationContext::end.
ModificadaAlta (8.8)1.3%—Webassembly Virtual Machine Project Webassembly Virtual Machine10/9/201817/6/2026
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::popAndValidateOperand.
ModificadaAlta (8.8)1.3%—Webassembly Virtual Machine Project Webassembly Virtual Machine10/9/201817/6/2026
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because Errors::unreachable() is reached.
ModificadaAlta (8.8)1.3%—Webassembly Virtual Machine Project Webassembly Virtual Machine10/9/201817/6/2026
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::else_.
ModificadaAlta (8.8)1.3%—Webassembly Virtual Machine Project Webassembly Virtual Machine10/9/201817/6/2026
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an IR::FunctionValidationContext::catch_all heap-based buffer over-read.
ModificadaMedia (6.5)2.6%—EMC RecoverpointEMC Recoverpoint FOR Virtual Machines29/5/201817/6/2026
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerability in the Boxmgmt CLI. An authenticated malicious user with boxmgmt privileges may potentially exploit this vulnerability to read RPA files. Note that files that require root…