Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 28% | — | Cisco Identity Services Engine | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an… | |
| Modificada | Media (5.4) | 0.61% | — | Cisco Identity Services Engine | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control on a feature within the web-based management interface of the… | |
| Modificada | Alta (8.8) | 31% | — | Cisco Identity Services Engine | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user input within requests as part of the web-based management… | |
| Modificada | Alta (8.1) | 0.57% | — | Oracle WEB Services Manager | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: XML Security component). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services Manager.… | |
| Modificada | Alta (7.6) | 0.71% | — | Sylabs Singularity Container Services Library | 17/1/2023 | 17/6/2026 | github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-client is used to pull a container image, with authentication, the HTTP Authorization header sent by the client to the library service may be incorrectly leaked to an S3… | |
| Modificada | Alta (8.6) | 0.51% | — | GNU Grub2Fedoraproject FedoraRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Power Little Endian EUS+4 | 14/12/2022 | 17/6/2026 | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this… | |
| Modificada | Media (6.1) | 0.43% | — | SAP Commerce Webservices 2.0 | 13/12/2022 | 17/6/2026 | Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to steal user… | |
| Analizada | Alta (7.5) | 0.53% | — | CertifiNetapp E-series Performance AnalyzerNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI | 7/12/2022 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root… | |
| Modificada | Media (6.5) | 0.53% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco Firepower Services Software FOR ASA | 15/11/2022 | 11/8/2026 | A vulnerability in the SSL/TLS client of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when a… | |
| Modificada | Alta (7.5) | 0.90% | — | Cisco Firepower Services Software FOR ASACisco Secure Firewall Management Center | 15/11/2022 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Prevention System (NGIPS) Software could allow an unauthenticated,… | |
| Modificada | Media (5.5) | 0.17% | — | Intel Server Platform Services Firmware | 11/11/2022 | 17/6/2026 | Missing release of memory after effective lifetime in firmware for Intel(R) SPS before versions SPS_E3_06.00.03.035.0 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Server Platform Services Firmware | 11/11/2022 | 17/6/2026 | Improper input validation in firmware for Intel(R) SPS before version SPS_E3_04.01.04.700.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.1) | 2.4% | — | Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+5 | 9/11/2022 | 10/8/2026 | Netlogon RPC Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 4.1% | — | Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+5 | 9/11/2022 | 10/8/2026 | Windows Kerberos Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.1) | 2.5% | — | Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019+5 | 9/11/2022 | 10/8/2026 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 2.7% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+5 | 9/11/2022 | 17/6/2026 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote… | |
| Modificada | Media (5.4) | 0.46% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Modificada | Alta (8.8) | 1.0% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (8.8) | 0.43% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the… | |
| Modificada | Alta (8.8) | 1.4% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker… | |
| Modificada | Media (5.3) | 0.88% | — | Cisco Identity Services Engine | 4/11/2022 | 17/6/2026 | A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources. An attacker could exploit… | |
| Modificada | Media (5.4) | 0.84% | — | Cisco Identity Services Engine | 26/10/2022 | 17/6/2026 | A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient input validation. An… | |
| Modificada | Alta (8.1) | 1.3% | — | Cisco Identity Services Engine | 26/10/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by… | |
| Modificada | Baja (3.7) | 1.6% | — | Oracle GraalvmOracle JDKOracle JREFedoraproject Fedora+11 | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows… | |
| Modificada | Media (5.3) | 2.3% | — | Oracle GraalvmOracle JDKOracle JREFedoraproject Fedora+11 | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable… |