Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 23% | — | Microsoft.powershell.archiveMicrosoft Powershell CoreMicrosoft Windows 10Microsoft Windows 7+6 | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008… | |
| Modificada | Alta (7.8) | 1.2% | — | Pdfforge PDF Architect | 10/11/2018 | 17/6/2026 | Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Data from Faulting Address controls Code Flow" issue. | |
| Modificada | Media (5.9) | 1.8% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 6/11/2018 | 17/6/2026 | IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and… | |
| Modificada | Media (4.3) | 0.98% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 6/11/2018 | 17/6/2026 | IBM Jazz based applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through… | |
| Modificada | Crítica (9.8) | 3.4% | — | Cisco Digital Network Architecture Center | 5/10/2018 | 17/6/2026 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have direct unauthorized access to critical management functions. The vulnerability is due to an insecure default configuration of the affected system. An attacker could… | |
| Modificada | Crítica (9.8) | 2.1% | — | Cisco Digital Network Architecture Center | 5/10/2018 | 17/6/2026 | A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due to insufficient security restrictions for critical… | |
| Modificada | Media (5.4) | 0.66% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality Manager+3 | 2/10/2018 | 17/6/2026 | IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Modificada | Crítica (9.8) | 1.7% | — | Slack Archivebot Project Slack Archivebot | 20/9/2018 | 17/6/2026 | SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute(). | |
| Modificada | Alta (7.5) | 12% | 💥 PoC | Opcfoundation Unified Architecture-.net-legacyOpcfoundation Unified Architecture-javaOpcfoundation Unified Architecture .net-standardOpcfoundation Unified Architecture Ansic+1 | 14/9/2018 | 17/6/2026 | Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests. | |
| Modificada | Crítica (9.1) | 2.3% | — | Siemens Simatic Wincc Open Architecture | 12/9/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC WinCC OA V3.14 and prior (All versions < V3.14-P021). Improper access control to a data point of the affected product could allow an unauthenticated remote user to escalate its privileges in the context of SIMATIC WinCC OA V3.14. This vulnerability could be exploited by… | |
| Modificada | Media (5.4) | 0.66% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+2 | 20/8/2018 | 17/6/2026 | Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425. | |
| Modificada | Media (5.4) | 0.85% | — | IBM Rational Doors Next GenerationIBM Rational Engineering Lifecycle ManagerIBM Rational Quality ManagerIBM Rational Rhapsody Design Manager+2 | 20/8/2018 | 17/6/2026 | Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655. | |
| Modificada | Alta (7.5) | 74% | — | Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+34 | 6/8/2018 | 17/6/2026 | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. | |
| Modificada | Media (5.5) | 2.5% | — | Archiver Project Archiver | 25/7/2018 | 17/6/2026 | mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Media (5.5) | 12% | 💥 PoC | Codehaus-plexus Plexus-archiverDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+1 | 25/7/2018 | 17/6/2026 | plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Selinc Acselerator Architect | 24/7/2018 | 17/6/2026 | SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization. Restart of the application is required. | |
| Modificada | Crítica (9.8) | 2.5% | — | Selinc Acselerator Architect | 24/7/2018 | 17/6/2026 | SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieval of arbitrary data, arbitrary code execution (in certain situations on specific platforms), and denial of service attacks. | |
| Modificada | Media (4.3) | 0.97% | — | IBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design Manager | 19/7/2018 | 17/6/2026 | IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 could reveal technical error messages to allow an adversary to gain information about the application and database that could be used to conduct… | |
| Modificada | Media (5.4) | 0.67% | — | IBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design Manager | 19/7/2018 | 17/6/2026 | IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Modificada | Media (5.4) | 0.67% | — | IBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design Manager | 19/7/2018 | 17/6/2026 | IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Modificada | Media (5.4) | 0.67% | — | IBM Rational Rhapsody Design ManagerIBM Rational Software Architect Design Manager | 19/7/2018 | 17/6/2026 | IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Modificada | Media (6.8) | 0.36% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 10/7/2018 | 17/6/2026 | IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 10/7/2018 | 17/6/2026 | IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026. | |
| Modificada | Media (4.3) | 0.89% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 6/7/2018 | 17/6/2026 | Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758. | |
| Modificada | Media (4.3) | 0.96% | — | IBM Rational Collaborative Lifecycle ManagementIBM Rational Team ConcertIBM Rational Doors Next GenerationIBM Rational Quality Manager+3 | 6/7/2018 | 17/6/2026 | IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from a stack trace that could be used to aid future attacks. IBM X-Force ID: 129719. |