Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.50% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization. | |
| Modificada | Alta (7.8) | 0.25% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system. | |
| Modificada | Alta (8.8) | 73% | 💥 Exploit | IBM Operational Decision Manager | 2/2/2024 | 17/6/2026 | IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146. | |
| Modificada | Crítica (9.8) | 76% | 💥 Exploit | IBM Operational Decision Manager | 2/2/2024 | 17/6/2026 | IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145. | |
| Modificada | Media (5.3) | 0.57% | — | Honeywell Controledge Unit Operations Controller FirmwareHoneywell Controledge Virtual Unit Operations Controller Firmware | 31/1/2024 | 17/6/2026 | An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limited information from the device. Honeywell recommends updating to the most… | |
| Modificada | Alta (7.5) | 0.78% | — | Honeywell Controledge Unit Operations Controller FirmwareHoneywell Controledge Virtual Unit Operations Controller Firmware | 30/1/2024 | 17/6/2026 | An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in… | |
| Modificada | Media (4.3) | 0.30% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 24/1/2024 | 17/6/2026 | Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also… | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (8.1) | 0.24% | — | Broadcom Fabric Operating System | 6/12/2023 | 17/6/2026 | Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could allow for the installation of forged or fraudulent license keys. This would allow attackers or a malicious party to forge a counterfeit license… | |
| Modificada | Media (5.9) | 0.29% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 22/11/2023 | 17/6/2026 | Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate. | |
| Modificada | Alta (7.8) | 0.28% | — | Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+2 | 21/11/2023 | 17/6/2026 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution. | |
| Modificada | Alta (7.8) | 0.28% | — | Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+2 | 20/11/2023 | 17/6/2026 | Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an integer overflow vulnerability in 'HeapTrack_alloc' and result in code execution. | |
| Modificada | Alta (7.8) | 0.28% | — | Real-time Operating SystemTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+2 | 20/11/2023 | 17/6/2026 | Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code execution. | |
| Modificada | Alta (7.1) | 0.22% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service. | |
| Modificada | Alta (7.8) | 0.24% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine. | |
| Modificada | Media (6.5) | 1.4% | — | Microsoft System Center Operations Manager | 14/11/2023 | 17/6/2026 | Open Management Infrastructure Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 0.60% | — | Mongodb Atlas Kubernetes Operator | 7/11/2023 | 17/6/2026 | The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. Please note that this is reported on an… | |
| Modificada | Alta (8.8) | 0.43% | — | Tibco HawkHawk Distribution FOR Tibco Silver FabricTibco Operational Intelligence Hawk RedtailTibco Runtime Agent | 25/10/2023 | 17/6/2026 | The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain… | |
| Modificada | Media (6.5) | 0.44% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 23/10/2023 | 17/6/2026 | Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 23/10/2023 | 17/6/2026 | Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit this vulnerability by authenticating to the device CLI and issuing certain commands. | |
| Modificada | Alta (7.5) | 0.47% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 23/10/2023 | 17/6/2026 | Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server. | |
| Modificada | Media (5.4) | 0.29% | — | Dell Unity Operating EnvironmentDell Unity XT Operating EnvironmentDell Unityvsa Operating Environment | 23/10/2023 | 17/6/2026 | Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can exploit these issues to obtain escalated privileges. | |
| Modificada | Alta (7.8) | 0.20% | — | Vmware Aria Operations FOR Logs | 20/10/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass. | |
| Modificada | Crítica (9.8) | 45% | 💥 PoC | Vmware Aria Operations FOR Logs | 20/10/2023 | 17/6/2026 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. | |
| Modificada | Media (6.1) | 0.98% | 💥 PoC | Mrpeng Mpoperationlogs | 18/10/2023 | 17/6/2026 | The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… |