Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1571 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.21%—Broadcom Fabric Operating System25/10/202217/6/2026
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.
ModificadaAlta (8.8)0.77%—Broadcom Fabric Operating System25/10/202217/6/2026
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin…
ModificadaMedia (4.9)0.64%—Vmware Vrealize Operations11/10/202217/6/2026
VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data.
ModificadaCrítica (9.8)1.0%—Redhat Openshift Service MeshRedhat Servicemesh-operator22/8/202217/6/2026
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…
ModificadaAlta (7.5)0.83%—Vmware Vrealize Operations10/8/202217/6/2026
VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.
ModificadaMedia (4.3)0.64%—Vmware Vrealize Operations10/8/202217/6/2026
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
ModificadaAlta (7.2)0.65%—Vmware Vrealize Operations10/8/202217/6/2026
VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.
ModificadaAlta (8.8)1.8%—Vmware Vrealize Operations10/8/20227/10/2026
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution.
ModificadaAlta (7.8)0.98%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.88%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.83%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.83%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.93%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaMedia (5.5)0.93%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaAlta (7.8)0.60%—Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager9/8/202217/6/2026
System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
ModificadaAlta (7.8)1.00%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)1.2%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.23%—Broadcom Fabric Operating System5/8/202217/6/2026
A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life published…
ModificadaAlta (7.8)0.22%—Aveva Batch ManagementAveva Enterprise Data ManagementAveva Manufacturing Execution SystemAveva Mobile Operator+327/7/202217/6/2026
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
ModificadaAlta (8.2)1.1%—Jenkins Compuware Ispw Operations27/7/202217/6/2026
Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
ModificadaMedia (4.3)0.68%—Jenkins Compuware Ispw Operations27/7/202217/6/2026
A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.
ModificadaMedia (5.3)1.6%—IBM Spectrum Protect Operations Center30/6/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.
ModificadaCrítica (9.8)1.1%—IBM Spectrum Protect Operations Center17/6/202217/6/2026
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain…
ModificadaAlta (7.8)2.2%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaAlta (7.8)2.5%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
Orbitaley — Vulnerabilidades