Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.35%—Huawei Nip6800 FirmwareHuawei S12700 FirmwareHuawei S2700 FirmwareHuawei S5700 Firmware+513/1/202117/6/2026
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions…
ModificadaMedia (6.5)0.32%—Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware24/12/202017/6/2026
There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal.
ModificadaMedia (6.3)0.33%—Spice-space Spice-vdagentDebian LinuxFedoraproject Fedora26/11/202017/6/2026
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this…
ModificadaMedia (5.5)0.44%—Spice-space Spice-vdagentDebian LinuxFedoraproject Fedora26/11/202017/6/2026
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents from connecting to the spice-vdagentd…
ModificadaMedia (6.4)0.30%—Spice-space Spice-vdagentDebian LinuxFedoraproject Fedora26/11/202017/6/2026
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this…
ModificadaMedia (5.5)0.50%—Spice-space Spice-vdagentDebian LinuxFedoraproject Fedora25/11/202017/6/2026
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or…
ModificadaCrítica (9.8)2.5%—Cisco DNA Spaces\18/11/202017/6/2026
A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied input in the web-based management interface. An attacker could…
ModificadaMedia (6.7)0.39%—Huawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+213/11/202017/6/2026
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command injection.Affected product versions include:NIP6300 versions…
ModificadaAlta (7.5)0.74%—Huawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+213/11/202017/6/2026
There is a denial of service vulnerability in some Huawei products. There is no protection against the attack scenario of specific protocol. A remote, unauthorized attackers can construct attack scenarios, which leads to denial of service.Affected product versions include:NIP6300 versions…
ModificadaAlta (8.8)0.33%—Tibco Iprocess Workspace Browser10/11/202017/6/2026
The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human…
ModificadaAlta (7.5)8.0%—Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+331/10/202017/6/2026
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still…
ModificadaMedia (6.5)1.7%—Jenkins Copy Data TO Workspace16/9/202017/6/2026
Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.
ModificadaAlta (7.5)1.5%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX Firmware31/8/202017/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.
ModificadaAlta (8.8)2.1%—Citrix Workspace24/7/202017/6/2026
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.
ModificadaCrítica (9.8)2.7%—Devspace23/7/202017/6/2026
The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote code execution.
ModificadaMedia (6.5)0.33%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+218/7/202017/6/2026
There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include:…
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaAlta (7.5)0.88%—Huawei Ar120-s FirmwareHuawei Ar1200 FirmwareHuawei Ar1200-s FirmwareHuawei Ar150 Firmware+468/7/202017/6/2026
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause…
ModificadaMedia (6.5)0.61%—Huawei Secospace Usg6300 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg6300e Firmware15/6/202017/6/2026
Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification. An attacker with limited privilege can exploit this vulnerability to access a specific directory. Successful…
ModificadaAlta (7.5)2.2%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space Management15/6/202017/6/2026
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow an attacker to bypass authentication due to improper session validation…
ModificadaMedia (5.4)0.82%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space Management15/6/202017/6/2026
IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker to hijack the clicking action of the victim. By persuading…
ModificadaAlta (7.8)0.58%💥 PoCCitrix Workspace APP8/6/202017/6/2026
Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
ModificadaAlta (7.8)0.57%💥 PoCCitrix Workspace APP8/6/202017/6/2026
Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.
ModificadaCrítica (9.8)0.88%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 Firmware+58/6/202017/6/2026
Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00; V500R002C10; V500R002C20; V500R002C30…
Orbitaley — Vulnerabilidades