Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.8% | — | NEC Expresscluster X | 30/1/2016 | 17/6/2026 | Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.7) | 5.7% | — | NTPSiemens TIM 4r-ie FirmwareSiemens TIM 4r-ie Dnp3 FirmwareNetapp Clustered Data Ontap+2 | 26/1/2016 | 17/6/2026 | NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key." | |
| Modificada | Media (4.6) | 0.40% | — | Oracle Solaris Cluster | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.2 allows local users to affect confidentiality, integrity, and availability via vectors related to HA for MySQL. | |
| Modificada | Media (4.3) | 1.8% | — | Redhat MOD Cluster | 24/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message. | |
| Modificada | Alta (7.5) | 3.0% | — | Redhat Enterprise Linux High AvailabilityRedhat Enterprise Linux Resilient StorageClusterlabs Pacemaker | 12/8/2015 | 17/6/2026 | Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command. | |
| Modificada | Media (4.3) | 2.6% | — | Redhat Enterprise LinuxClusterlabs Pacemaker | 23/11/2013 | 16/6/2026 | Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking). | |
| Modificada | Media (4.3) | 2.6% | — | Redhat Jboss Enterprise Application PlatformRedhat MOD Cluster | 22/10/2012 | 16/6/2026 | mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context… | |
| Modificada | Media (4.9) | 0.95% | — | Cluster Resources Torque Resource ManagerClusterresources Torque Resource Manager | 13/1/2012 | 16/6/2026 | Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors. | |
| Modificada | Alta (10) | 6.6% | — | Symantec Veritas Dynamic Multi-pathingSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System FOR Oracle RACSymantec Netbackup Puredisk | 19/8/2011 | 16/6/2026 | Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Veritas Storage Foundation Cluster File System (SFCFS) 5.1 and earlier, Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 and earlier,… | |
| Modificada | Alta (7.5) | 2.9% | — | Clusterresources Torque Resource Manager | 15/8/2011 | 16/6/2026 | Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program. | |
| Modificada | Media (6.1) | 0.37% | — | Oracle Solaris Cluster | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in Oracle Solaris Cluster 3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Data Service for WebLogic Server. | |
| Modificada | Alta (8.5) | 2.5% | — | Clusterresources Torque Resource Manager | 24/6/2011 | 16/6/2026 | Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.x before 2.4.14, 2.5.x before 2.5.6, and 3.x before 3.0.2 allow (1) remote authenticated users to gain privileges via a long Job_Name field in a qsub command to the server, and might allow (2) local users to… | |
| Modificada | Baja (1.9) | 0.27% | — | SUN Cluster | 8/2/2010 | 16/6/2026 | Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file. | |
| Modificada | Media (6.2) | 0.31% | — | HP Enterprise Cluster Master Toolkit | 3/2/2010 | 16/6/2026 | Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.11.31 (11i v3) allows local users to gain access to an Oracle or Sybase database via unknown vectors. | |
| Modificada | Alta (10) | 11% | — | Symantec Backup Exec Continuous Protection ServerSymantec Veritas Application DirectorSymantec Veritas Backup ExecSymantec Veritas Cluster Server+19 | 11/12/2009 | 16/6/2026 | VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA)… | |
| Modificada | Alta (7.2) | 0.33% | — | SUN Cluster | 28/9/2009 | 16/6/2026 | Unspecified vulnerability in clsetup in the configuration utility in Sun Solaris Cluster 3.2 allows local users to gain privileges via unknown vectors. | |
| Modificada | Media (6.9) | 0.38% | — | Redhat Cluster ProjectRedhat CmanRedhat RgmanagerFedoraproject Fedora+1 | 30/3/2009 | 16/6/2026 | Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9. | |
| Modificada | Alta (7.2) | 0.33% | — | SUN Cluster | 3/6/2008 | 16/6/2026 | The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users to read data from arbitrary deleted files, or corrupt files in global filesystems, via unspecified vectors. | |
| Modificada | Media (4.6) | 0.50% | — | HP Cluster Object ManagerHP Serviceguard | 19/7/2007 | 16/6/2026 | Unspecified vulnerability in HP ServiceGuard for Linux for Red Hat Enterprise Linux (RHEL) 2.1 SG A.11.14.04 through A.11.14.06; RHEL 3.0 SG A.11.16.04 through A.11.16.10; and ServiceGuard Cluster Object Manager B.03.01.02 allows local users to gain privileges via unspecified vectors, a different vulnerability than… | |
| Modificada | Media (4.6) | 0.52% | — | Redhat Cluster Suite | 25/6/2007 | 16/6/2026 | Buffer overflow in cluster/cman/daemon/daemon.c in cman (redhat-cluster-suite) before 20070622 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long client messages. | |
| Modificada | Media (5) | 0.98% | — | Redhat Cluster Suite | 25/6/2007 | 16/6/2026 | daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensitive information from previous requests. | |
| Modificada | Media (6.8) | 1.6% | — | SUN Cluster | 25/4/2007 | 16/6/2026 | Unspecified vulnerability in Sun Cluster 3.1 and Solaris Cluster 3.2 before 20070424 allows remote authenticated users, operating from a different cluster node, to cause a denial of service (data corruption or send_mondo panic) via unspecified vectors, as demonstrated by EMC Symcli backup software 6.2.1. | |
| Modificada | Alta (7.2) | 0.34% | — | Cluster Resources Torque Resource Manager | 3/11/2006 | 16/6/2026 | resmom/start_exec.c in pbs_mom in TORQUE Resource Manager 2.0.0p8 and earlier allows local users to create arbitrary files via a symlink attack on (1) a job output file in /usr/spool/PBS/spool and possibly (2) a job file in /usr/spool/PBS/mom_priv/jobs. | |
| Modificada | Media (4.6) | 0.93% | 💥 Exploit | Rocks Clusters | 21/7/2006 | 16/6/2026 | Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system function call. | |
| Modificada | Baja (1.7) | 0.30% | — | SUN Cluster | 4/4/2006 | 16/6/2026 | Unspecified vulnerability in SunPlex Manager in Sun Cluster 3.1 4/04 allows local users with solaris.cluster.gui authorization to view arbitrary files via unspecified vectors. |