Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.95% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Cf-release | 28/11/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a… | |
| Modificada | Alta (7.5) | 1.4% | — | Pivotal Software Cf-deployment | 27/11/2017 | 17/6/2026 | In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained to unintended locations. | |
| Modificada | Media (5.4) | 0.78% | — | Octopus Deploy | 14/11/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter. | |
| Modificada | Alta (7.5) | 40% | 💥 PoC | OpensslDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+41 | 13/11/2017 | 17/6/2026 | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections… | |
| Modificada | Media (5.4) | 0.77% | — | Octopus Deploy | 13/11/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter. | |
| Modificada | Media (6.5) | 0.73% | — | Octopus Deploy | 19/10/2017 | 17/6/2026 | In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges. | |
| Modificada | Media (6.5) | 0.60% | — | Octopus Deploy | 19/10/2017 | 17/6/2026 | An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by Octopus, including the private key. | |
| Modificada | Alta (7.5) | 0.81% | — | Octopus Deploy | 19/10/2017 | 17/6/2026 | Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offline Drop Targets. | |
| Modificada | Crítica (9.1) | 1.9% | — | Redhat Edeploy | 16/10/2017 | 17/6/2026 | Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a .. (dot dot) the session parameter. | |
| Modificada | Media (5.5) | 0.37% | — | Jenkins Deploy | 5/10/2017 | 17/6/2026 | The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkins master local file system access, or users with Extended Read access to the jobs it is used in, to retrieve those passwords. The Deploy to container Plugin now integrates with Credentials Plugin to… | |
| Modificada | Crítica (9.8) | 3.0% | — | Redhat Edeploy | 19/9/2017 | 17/6/2026 | eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files. | |
| Modificada | Alta (8.8) | 0.55% | — | IBM Urbancode Deploy | 28/8/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier. | |
| Modificada | Media (5.7) | 1.2% | — | Octopus DeployOctopus Server | 17/7/2017 | 17/6/2026 | In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value. | |
| Modificada | Alta (8.1) | 1.5% | — | IBM Urbancode Deploy | 25/4/2017 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 122202. | |
| Modificada | Media (5.4) | 0.52% | — | IBM Urbancode Deploy | 8/3/2017 | 17/6/2026 | IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: C1000264. | |
| Modificada | Alta (7.5) | 1.9% | — | Netapp Ontap Select Deploy Administration Utility | 1/3/2017 | 17/6/2026 | The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Urbancode Deploy | 1/2/2017 | 17/6/2026 | IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent. | |
| Modificada | Crítica (10) | 2.8% | — | IBM Urbancode Deploy | 1/2/2017 | 17/6/2026 | IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production applications. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Urbancode Deploy | 1/2/2017 | 17/6/2026 | IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResource secured role properties. | |
| Modificada | Alta (7.5) | 0.82% | — | IBM Urbancode Deploy | 1/2/2017 | 17/6/2026 | IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine. | |
| Modificada | Media (5.5) | 0.35% | — | IBM Urbancode Deploy | 1/2/2017 | 17/6/2026 | IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user. | |
| Modificada | Media (4.3) | 0.59% | — | IBM Urbancode Deploy | 1/2/2017 | 17/6/2026 | IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes. | |
| Modificada | Media (5.4) | 0.64% | — | IBM Urbancode Deploy | 1/12/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Alta (7) | 84% | ⚠ Explotación activa💥 Exploit | Canonical Ubuntu LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 10/11/2016 | 17/6/2026 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW." | |
| Modificada | Media (5.7) | 1.8% | — | Oracle Siebel Engineering-installer AND Deployment | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Siebel Engineering - Installer and Deployment component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Web Server. |