Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
634 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.6% | — | Gridgain | 10/10/2017 | 17/6/2026 | Directory traversal vulnerability in the Visor GUI Console in GridGain before 1.7.16, 1.8.x before 1.8.12, 1.9.x before 1.9.7, and 8.x before 8.1.5 allows remote authenticated users to read arbitrary files on remote cluster nodes via a crafted path. | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Connected Grid Network Management SystemCisco IOT Field Network Director | 7/9/2017 | 17/6/2026 | A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart, aka Memory Exhaustion. The vulnerability is due to insufficient rate-limiting… | |
| Modificada | Media (6.5) | 1.6% | — | Netapp Storagegrid Webscale | 29/8/2017 | 17/6/2026 | NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors. | |
| Modificada | Alta (7.8) | 3.2% | — | Phpgrid | 18/8/2017 | 17/6/2026 | Directory traversal vulnerability in ajaxfileupload.php in Kayson Group Ltd. phpGrid before 7.2.5 allows remote attackers to execute arbitrary code by uploading a crafted file with a .. (dot dot) in the file name. | |
| Modificada | Alta (7.5) | 57% | — | Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerNetapp Storagegrid+9 | 20/6/2017 | 17/6/2026 | The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force… | |
| Modificada | Crítica (9.8) | 20% | — | Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerNetapp Storagegrid+10 | 20/6/2017 | 17/6/2026 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed. | |
| Modificada | Alta (7.5) | 74% | 💥 Exploit | Exagrid Ex3000 FirmwareExagrid Ex5000 FirmwareExagrid Ex7000 FirmwareExagrid Ex10000e Firmware+4 | 21/4/2017 | 17/6/2026 | ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image. | |
| Modificada | Crítica (9.8) | 72% | 💥 Exploit | Exagrid Ex3000 FirmwareExagrid Ex5000 FirmwareExagrid Ex7000 FirmwareExagrid Ex10000e Firmware+4 | 21/4/2017 | 17/6/2026 | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session. | |
| Modificada | Alta (7.5) | 11% | — | NettyRedhat Jboss Data GridRedhat Jboss Middleware Text-only AdvisoriesApache Cassandra | 13/4/2017 | 17/6/2026 | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). | |
| Modificada | Alta (8.1) | 1.1% | — | Cisco AMP Threat Grid Appliance | 7/7/2016 | 17/6/2026 | The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify interprocess data, via a crafted malware sample. | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Oracle JDKOracle JREOracle JrockitOracle Linux+34 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | |
| Modificada | Media (6.1) | 0.91% | — | Tollgrade Smartgrid Lighthouse Sensor Management System | 13/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 2.1% | — | Tollgrade Smartgrid Lighthouse Sensor Management System | 13/2/2016 | 17/6/2026 | Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspecified vectors. | |
| Modificada | Media (5.3) | 1.2% | — | Tollgrade Smartgrid Lighthouse Sensor Management System | 13/2/2016 | 17/6/2026 | Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.60% | — | Tollgrade Smartgrid Lighthouse Sensor Management System | 13/2/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (5) | 22% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0482,… | |
| Modificada | Media (5) | 22% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0477 and CVE-2016-0478. NOTE:… | |
| Modificada | Media (5.2) | 0.36% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality and availability via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (4.6) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than… | |
| Modificada | Media (4.6) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than… | |
| Modificada | Baja (2.1) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (4.6) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (4.4) | 0.38% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than… | |
| Modificada | Media (4.3) | 1.6% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 12.1.0.4, and 12.1.0.5 allows remote attackers to affect confidentiality via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (6.5) | 1.6% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Loader Service. |