Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.21%—BitvisorAI16/10/202517/6/2026
An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of service (host hypervisor crash) via a crafted PCI configuration space access. Given it's a heap overflow in a privileged hypervisor context,…
En análisisMedia (5.1)0.13%—IBM Powervm Hypervisor14/9/202517/6/2026
IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to cause a denial of service by issuing a specially crafted IBM i hypervisor call that would disclose memory contents or consume excessive memory resources.
AplazadaAlta (7.4)0.28%—Microsoft Windows Defender Application ControlAIMicrosoft Hypervisor-protected Code IntegrityAI8/9/202517/6/2026
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier…
AnalizadaMedia (6.7)0.14%—IBM Transformation Advisor3/9/202517/6/2026
IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image.
AnalizadaCrítica (9.3)0.52%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.
AnalizadaAlta (8.6)0.22%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade.
AnalizadaCrítica (9.2)0.47%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.
AnalizadaAlta (8.7)0.34%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously crash the application services.
AnalizadaMedia (5.1)0.20%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can inject a stored XSS to the floorplan web page.
AnalizadaAlta (7.7)0.26%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services.
AnalizadaAlta (8.8)0.36%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can access any file from the E3 file system.
AnalizadaMedia (5.3)0.31%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash.
AnalizadaMedia (6.9)0.34%—Copeland E3 Supervisory Controller Firmware2/9/20255/10/2026
E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.
AplazadaMedia (5.9)0.22%—Kevin Heath Tripadvisor ShortcodeAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kevin heath Tripadvisor Shortcode tripadvisor-shortcode allows Stored XSS.This issue affects Tripadvisor Shortcode: from n/a through <= 2.2.
AnalizadaAlta (8.8)0.26%—AI SEO Link Advisor Project AI SEO Link Advisor15/8/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advisor: from 0.0.0 before 1.0.6.
AnalizadaMedia (5.5)0.14%—Dell TechadvisorDell Xtremio Management Server30/7/202517/6/2026
Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed credentials to access the vulnerable…
AnalizadaMedia (5.5)0.14%—Dell TechadvisorDell Xtremio Management Server30/7/202517/6/2026
TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed credentials…
AnalizadaAlta (7.5)1.7%—Mywebsiteadvisor Simple Backup19/7/202517/6/2026
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the…
AnalizadaAlta (8.4)0.16%—Sensopart Visor Vision Sensors Firmware23/6/202517/6/2026
An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges.
AplazadaMedia (6.5)0.17%—Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI16/5/202517/6/2026
Bypass Connection Restriction vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component), Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before…
AnalizadaAlta (8.8)0.56%—Jenkins Health Advisor BY Cloudbees14/5/202517/6/2026
Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses.
AnalizadaMedia (5.4)0.15%—Intel AdvisorIntel Oneapi Base Toolkit13/5/202517/6/2026
Uncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6.8)0.07%—Google Gvisor28/3/202517/6/2026
Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to incorrect handling of file access permissions, which allowed unprivileged users to access restricted files. This occurred because the process initially ran with root-like permissions until the first fork.
AnalizadaMedia (4.4)0.13%—IBM Powervm Hypervisor28/3/202517/6/2026
IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certain Linux processor combability mode configurations, to cause undetected data loss or errors when performing gzip compression using HW acceleration.
AnalizadaMedia (4.1)0.29%—IBM Qradar Advisor18/3/202517/6/2026
IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.