Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 72% | ⚠ Explotación activa💥 Exploit | Google AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+73 | 11/10/2019 | 17/6/2026 | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing… | |
| Modificada | Media (5.3) | 0.93% | — | SAP Process Integration | 8/10/2019 | 17/6/2026 | SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check | |
| Modificada | Media (4.3) | 0.55% | — | SAP Netweaver Process Integration | 8/10/2019 | 17/6/2026 | SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check. | |
| Modificada | Alta (7.5) | 8.9% | — | Bouncycastle Bc-javaApache TomeeNetapp Active IQ Unified ManagerNetapp Oncommand API Services+17 | 8/10/2019 | 17/6/2026 | The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64. | |
| Modificada | Alta (7.5) | 3.5% | — | Linux KernelOpensuse LeapNetapp AFF A700s FirmwareNetapp H300s Firmware+13 | 30/9/2019 | 17/6/2026 | In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d. | |
| Modificada | Alta (7.8) | 0.91% | — | Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Compute Node EUS+35 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.87% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Real Time+30 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.62% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+30 | 17/9/2019 | 17/6/2026 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could… | |
| Modificada | Media (4.3) | 0.70% | — | SAP Netweaver Process Integration | 10/9/2019 | 17/6/2026 | Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. | |
| Modificada | Media (5.4) | 0.68% | — | IBM Business Automation WorkflowIBM Business Process Manager | 5/9/2019 | 17/6/2026 | IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary… | |
| Modificada | Media (5.6) | 0.61% | — | Linux KernelNetapp Active IQ Performance Analytics ServicesNetapp Service ProcessorDebian Linux+2 | 4/9/2019 | 17/6/2026 | A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre… | |
| Modificada | Alta (7.5) | 1.9% | — | Newgensoft Omniflow Intelligent Business Process Suite | 21/8/2019 | 17/6/2026 | Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side and fetched from the server every time the user visits the D, creating business confusion. In the… | |
| Modificada | Alta (8.2) | 2.4% | — | IBM Business Automation WorkflowIBM Business Process Manager | 20/8/2019 | 17/6/2026 | IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162770. | |
| Modificada | Media (5.7) | 1.2% | — | IBM Business Automation WorkflowIBM Business Process Manager | 20/8/2019 | 17/6/2026 | IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive information from another user by inserting links that would be clicked on by unsuspecting users. IBM X-Force ID: 162771. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Processor Identification Utility | 19/8/2019 | 17/6/2026 | Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows before version 6.1.0731 may allow an authenticated user to potentially enable escalation of privilege, denial of service or information disclosure via local access. | |
| Modificada | Media (6.1) | 0.84% | — | SAP Netweaver Process Integration | 14/8/2019 | 17/6/2026 | Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url thereby resulting in Reflected Cross-Site Scripting (XSS) vulnerability | |
| Modificada | Media (6.3) | 0.89% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Crítica (9.4) | 2.4% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Media (5.4) | 0.71% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Crítica (9.4) | 4.3% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Crítica (9.4) | 5.1% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Alta (8.8) | 2.3% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Analizada | Alta (7.8) | 52% | ⚠ Explotación activa💥 Exploit | Linux KernelDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+18 | 17/7/2019 | 17/6/2026 | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges… | |
| Modificada | Alta (7.8) | 0.41% | — | Intel Processor Diagnostic Tool | 11/7/2019 | 17/6/2026 | Improper access control in the Intel(R) Processor Diagnostic Tool before version 4.1.2.24 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access. | |
| Modificada | Alta (7.2) | 3.4% | — | SAP Netweaver Process Integration | 10/7/2019 | 17/6/2026 | ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system. |