Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)45%—Oracle Hospitality Opera 5 Property Services18/4/202317/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI). The supported version that is affected is 5.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property…
ModificadaMedia (4.3)0.49%—Oracle Financial Services Behavior Detection Platform18/4/202317/6/2026
Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application). The supported version that is affected is 8.0.8.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaAlta (7.8)0.20%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more…
ModificadaMedia (6.7)0.20%—Cisco Evolved Programmable Network ManagerCisco Identity Services EngineCisco Prime Infrastructure5/4/202317/6/2026
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6)0.75%—Cisco Identity Services Engine5/4/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaAlta (7.8)1.9%💥 PoCLinux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+927/3/202317/6/2026
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
ModificadaAlta (7.8)0.90%—X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1427/3/202317/6/2026
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote…
En análisisAlta (8.8)1.6%⚠ Explotación activaWebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+196/3/20237/10/2026
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
ModificadaMedia (6.1)0.74%—Cisco Identity Services Engine1/3/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation…
ModificadaCrítica (9.8)0.66%—Online Services Project Online Services23/2/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17.
ModificadaAlta (7.5)20%💥 PoCPythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+217/2/202317/6/2026
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
ModificadaMedia (4.4)0.19%—Intel Server Platform Services16/2/202317/6/2026
Improper condition check in some Intel(R) SPS firmware before version SPS_E3_06.00.03.300.0 may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.20%—Intel Server Platform Services16/2/202317/6/2026
Active debug code in some Intel (R) SPS firmware before version SPS_E5_04.04.04.300.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.3)0.93%—Microsoft SQL Server 2019 Integration ServicesMicrosoft SQL Server 2022 Integration Services14/2/202319/8/2026
Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability
ModificadaAlta (8.8)1.5%—Cisco Ic3000 Industrial Compute GatewayCisco IOXCisco IOS XECisco Cgr1240 Firmware+512/2/202317/6/2026
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An…
ModificadaAlta (8.8)0.95%—Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+91/2/202317/6/2026
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
ModificadaMedia (5.5)1.2%—Cisco Network Services Orchestrator20/1/202317/6/2026
A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the attacker must be a member of the admin group. This…
ModificadaAlta (8.6)0.86%—Cisco Broadworks Application Delivery Platform Device ManagementCisco Broadworks Xtended Services Platform20/1/202317/6/2026
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input…
ModificadaMedia (6.1)0.59%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform20/1/202317/6/2026
A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of…
ModificadaMedia (5.4)0.54%—Cisco Identity Services Engine20/1/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an…