Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1571 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.90%—Veritas Infoscale Operations Manager17/7/202317/6/2026
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
ModificadaAlta (7.8)0.60%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue14/6/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
ModificadaMedia (6.1)0.38%—Wpoperation Salert - Fake Sales Notification Woocommerce12/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPoperation SALERT – Fake Sales Notification WooCommerce plugin <= 1.2.1 versions.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitVmware Aria Operations FOR Networks7/6/202317/6/2026
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
ModificadaMedia (6.7)0.22%—Vmware Aria OperationsVmware Cloud Foundation12/5/202317/6/2026
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
ModificadaMedia (6.7)0.18%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.
ModificadaAlta (7.2)1.0%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
ModificadaAlta (8.8)0.65%—Vmware Cloud FoundationVmware Vrealize Operations12/5/202317/6/2026
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
ModificadaCrítica (9.8)0.58%—Veritas Infoscale Operations Manager10/5/202317/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the…
ModificadaAlta (7.2)0.70%—Veritas Infoscale Operations Manager10/5/202317/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage…
ModificadaMedia (5.5)0.19%—Linuxfoundation Baremetal Operator26/4/202317/6/2026
Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This causes the plain-text username and hashed…
ModificadaAlta (7.2)1.6%—Vmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
ModificadaCrítica (9.8)70%💥 ExploitVmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
ModificadaAlta (7.2)45%—Oracle Hospitality Opera 5 Property Services18/4/202317/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI). The supported version that is affected is 5.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property…
ModificadaMedia (5.5)1.3%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+730/3/202317/6/2026
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the…
ModificadaMedia (5.9)1.9%—Haxx LibcurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapBroadcom Brocade Fabric Operating System Firmware+530/3/202317/6/2026
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads…
ModificadaAlta (8.8)2.2%—Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerBroadcom Brocade Fabric Operating System Firmware+530/3/202317/6/2026
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw…
ModificadaCrítica (9.8)2.3%—Openbsd OpensshNetapp Brocade Fabric Operating SystemNetapp HCI Bootstrap OSNetapp Solidfire Element OS17/3/202314/7/2026
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
ModificadaAlta (8.8)0.35%—ABB Symphony Plus S+ Operations2/3/202317/6/2026
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
ModificadaMedia (6.7)0.22%—Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+823/2/202317/6/2026
A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands…
ModificadaCrítica (9.1)0.54%—Ricoh MP C307 FirmwareRicoh MP C407 FirmwareRicoh MP C406 FirmwareRicoh MP C306 Firmware+7316/2/202317/6/2026
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
ModificadaMedia (6.5)0.47%—Tibco HawkTibco Operational Intelligence Hawk Redtail14/2/202317/6/2026
The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO…
ModificadaMedia (5.9)0.45%—Dell EMC Unity Operating EnvironmentDell EMC Unity XT Operating EnvironmentDell EMC Unityvsa Operating Environment14/2/202317/6/2026
Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.
ModificadaBaja (2.1)0.29%—Samsung ONE Hand Operation +9/2/202317/6/2026
Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner&#39;s widget without authorization via gesture setting.
AnalizadaAlta (7.5)83%⚠ Explotación activa💥 ExploitTerra-master Terramaster Operating System7/2/202317/6/2026
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.
Orbitaley — Vulnerabilidades