Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

754 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)23%—Microsoft.powershell.archiveMicrosoft Powershell CoreMicrosoft Windows 10Microsoft Windows 7+614/11/201817/6/2026
A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008…
ModificadaAlta (7.8)1.2%—Pdfforge PDF Architect10/11/201817/6/2026
Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Data from Faulting Address controls Code Flow" issue.
ModificadaMedia (5.9)1.8%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+36/11/201817/6/2026
IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and…
ModificadaMedia (4.3)0.98%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+36/11/201817/6/2026
IBM Jazz based applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through…
ModificadaCrítica (9.8)3.4%—Cisco Digital Network Architecture Center5/10/201817/6/2026
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have direct unauthorized access to critical management functions. The vulnerability is due to an insecure default configuration of the affected system. An attacker could…
ModificadaCrítica (9.8)2.1%—Cisco Digital Network Architecture Center5/10/201817/6/2026
A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient security restrictions for critical…
ModificadaMedia (5.4)0.66%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+32/10/201817/6/2026
IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
ModificadaCrítica (9.8)1.7%—Slack Archivebot Project Slack Archivebot20/9/201817/6/2026
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().
ModificadaAlta (7.5)12%💥 PoCOpcfoundation Unified Architecture-.net-legacyOpcfoundation Unified Architecture-javaOpcfoundation Unified Architecture .net-standardOpcfoundation Unified Architecture Ansic+114/9/201817/6/2026
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
ModificadaCrítica (9.1)2.3%—Siemens Simatic Wincc Open Architecture12/9/201817/6/2026
A vulnerability has been identified in SIMATIC WinCC OA V3.14 and prior (All versions < V3.14-P021). Improper access control to a data point of the affected product could allow an unauthenticated remote user to escalate its privileges in the context of SIMATIC WinCC OA V3.14. This vulnerability could be exploited by…
ModificadaMedia (5.4)0.66%—IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+220/8/201817/6/2026
Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425.
ModificadaMedia (5.4)0.85%—IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+220/8/201817/6/2026
Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655.
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaMedia (5.5)2.5%—Archiver Project Archiver25/7/201817/6/2026
mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaMedia (5.5)12%💥 PoCCodehaus-plexus Plexus-archiverDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+125/7/201817/6/2026
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaAlta (7.5)7.8%💥 ExploitSelinc Acselerator Architect24/7/201817/6/2026
SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization. Restart of the application is required.
ModificadaCrítica (9.8)2.5%—Selinc Acselerator Architect24/7/201817/6/2026
SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieval of arbitrary data, arbitrary code execution (in certain situations on specific platforms), and denial of service attacks.
ModificadaMedia (4.3)0.97%—IBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design Manager19/7/201817/6/2026
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 could reveal technical error messages to allow an adversary to gain information about the application and database that could be used to conduct…
ModificadaMedia (5.4)0.67%—IBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design Manager19/7/201817/6/2026
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…
ModificadaMedia (5.4)0.67%—IBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design Manager19/7/201817/6/2026
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…
ModificadaMedia (5.4)0.67%—IBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design Manager19/7/201817/6/2026
IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…
ModificadaMedia (6.8)0.36%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+310/7/201817/6/2026
IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.
ModificadaMedia (6.5)1.1%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+310/7/201817/6/2026
IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026.
ModificadaMedia (4.3)0.89%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+36/7/201817/6/2026
Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758.
ModificadaMedia (4.3)0.96%—IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+36/7/201817/6/2026
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 129719.
Orbitaley — Vulnerabilidades