Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.80% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 5/6/2020 | 17/6/2026 | Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal. | |
| Modificada | Alta (7.8) | 0.47% | — | Ivanti Workspace Control | 18/5/2020 | 17/6/2026 | In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights. | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Analizada | Media (6.5) | 86% | ⚠ Explotación activa💥 Exploit | Saltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2 | 30/4/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jetbrains Space | 22/4/2020 | 17/6/2026 | In JetBrains Space through 2020-04-22, the password authentication implementation was insecure. | |
| Modificada | Alta (7.5) | 0.83% | — | Jetbrains Space | 22/4/2020 | 17/6/2026 | In JetBrains Space through 2020-04-22, the session timeout period was configured improperly. | |
| Modificada | Media (5.4) | 0.52% | — | Jetbrains Space | 22/4/2020 | 17/6/2026 | JetBrains Space through 2020-04-22 allows stored XSS in Chats. | |
| Modificada | Media (5.4) | 0.55% | — | Matrix42 Workspace Management | 15/4/2020 | 17/6/2026 | The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues. | |
| Modificada | Media (5.4) | 0.77% | — | Matrix42 Workspace Management | 15/4/2020 | 17/6/2026 | Matrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software. | |
| Modificada | Media (5.5) | 0.48% | — | Ivanti Workspace Control | 4/4/2020 | 17/6/2026 | Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material). | |
| Modificada | Alta (8.1) | 0.81% | — | Huawei Secospace Antiddos8000 Firmware | 20/3/2020 | 17/6/2026 | Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the peer device to send specific packets to the affected device. Due to the improper implementation of the authentication function, attackers can exploit the vulnerability to… | |
| Modificada | Crítica (9.8) | 2.9% | — | Ivanti Workspace Control | 19/3/2020 | 17/6/2026 | An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protection by renaming the WMTemp work folder used by PowerGrid. A malicious PowerGrid XML file can then be created, after which the folder is renamed back to its original value. Also, CVE-2018-15591… | |
| Modificada | Alta (7.5) | 0.79% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 FirmwareHuawei Oceanstor 5310 Firmware | 28/2/2020 | 17/6/2026 | NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have have a resource management error vulnerability. An attacker needs to perform specific operations to trigger a function of the affected device. Due to improper resource management of the function, the… | |
| Modificada | Media (4.4) | 0.20% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 28/2/2020 | 17/6/2026 | NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when administrator log in to the device and performs some operations. Successful exploit could cause certain process reboot. | |
| Modificada | Alta (7.5) | 0.76% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 28/2/2020 | 17/6/2026 | NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds write vulnerability. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which… | |
| Modificada | Media (5.5) | 0.20% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 28/2/2020 | 17/6/2026 | NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when an abnormal condition occurs in certain operation. Successful exploit could cause certain process reboot. Affected… | |
| Modificada | Media (5.5) | 0.20% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 28/2/2020 | 17/6/2026 | NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer access vulnerability. The software system access an invalid pointer when operator logs in to the device and performs some operations. Successful exploit could cause certain process reboot. | |
| Modificada | Alta (7.5) | 0.77% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 28/2/2020 | 17/6/2026 | NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message,… | |
| Modificada | Alta (7.5) | 0.66% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 28/2/2020 | 17/6/2026 | NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access control bypass vulnerability. Attackers that can access to the internal network can exploit this vulnerability with careful deployment. Successful exploit may cause the access control to be… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Apache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+17 | 24/2/2020 | 25/8/2026 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.… | |
| Modificada | Media (5.3) | 0.41% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 18/2/2020 | 17/6/2026 | Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Dangling pointer dereference vulnerability. An authenticated attacker may do some special operations in the affected products… | |
| Modificada | Media (5.3) | 0.73% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 18/2/2020 | 17/6/2026 | Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a vulnerability that a memory management error exists when IPSec Module handing a specific message. This causes 1 byte… | |
| Modificada | Alta (7.5) | 0.86% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 18/2/2020 | 17/6/2026 | Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Denial of Service (DoS) vulnerability. Due to improper processing of specific IPSEC packets, remote attackers can send… | |
| Modificada | Alta (7.5) | 0.72% | — | Huawei Nip6800 FirmwareHuawei Secospace Usg6600 FirmwareHuawei Usg9500 Firmware | 18/2/2020 | 17/6/2026 | Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a memory leak vulnerability. The software does not sufficiently track and release allocated memory while parse certain message,… | |
| Modificada | Alta (7.5) | 0.76% | — | Huawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Secospace Usg6500 Firmware+2 | 17/2/2020 | 17/6/2026 | Huawei NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, and USG9500 versions V500R001C30, V500R001C60, and V500R005C00 have an information leakage vulnerability. An attacker can exploit this vulnerability by sending specific request packets to affected devices. Successful exploit may lead to… |