Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

366 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.4)0.31%—ABB Ability EdgeniusAI20/11/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects ABB Ability Edgenius: 3.2.0.0, 3.2.1.1.
AnalizadaMedia (4.4)0.23%—Solarwinds Observability Self-hosted18/11/202517/6/2026
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.
AnalizadaMedia (5.4)0.28%—Solarwinds Observability Self-hosted18/11/202517/6/2026
SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.
AplazadaAlta (8.8)0.33%—Observability OperatorAI12/11/202521/9/2026
A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create…
AnalizadaMedia (4.6)0.24%—Solarwinds Observability Self-hosted21/10/202517/6/2026
SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege account.
AplazadaMedia (6.4)0.20%—Vulnerability-lookupAI25/9/202530/9/2026
vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and user.py, by a user on a vulnerability-lookup instance who can add bundles, comments, or sightings. A cross-site scripting (XSS) vulnerability was discovered in the handling of user-supplied input in the Bundles, Comments, and Sightings components.…
AplazadaAlta (8.7)0.36%—ABB Ability ZenonAI13/8/202517/6/2026
Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.
AplazadaMedia (4.8)0.15%—Intel Local Manageability ServiceAI12/8/202517/6/2026
Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2514.7.16.0 may allow an authenticated user to potentially enable information disclosure via local access.
AplazadaMedia (5.9)0.33%—Intel AMTAIIntel Standard ManageabilityAI12/8/202517/6/2026
Out-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via network access.
AnalizadaAlta (7.8)0.29%—Solarwinds Observability Self-hosted24/7/202517/6/2026
SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from a low-level account…
AplazadaMedia (5.9)0.73%—Trustyai ExplainabilityAI20/6/202517/6/2026
A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted LMEvalJob by a user with permissions to deploy…
AnalizadaMedia (4.3)0.21%—Solarwinds Observability Self-hosted10/6/202517/6/2026
SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.
AnalizadaMedia (4.8)0.19%—Solarwinds Observability Self-hosted10/6/202517/6/2026
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.
AplazadaMedia (5.4)0.32%—Ability INC Accessibility SuiteAI6/6/202517/6/2026
Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Suite: from n/a through <= 4.19.
AnalizadaAlta (7.8)0.16%—AMD Aim-t Manageability API13/5/202517/6/2026
Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AnalizadaAlta (7.8)0.16%—AMD Aim-t Manageability API13/5/202517/6/2026
A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
AplazadaAlta (7.3)0.22%—AMD Cloud Manageability ServiceAI13/5/202517/6/2026
Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.
AplazadaAlta (7.3)0.22%—Aim-t Manageability ServiceAI13/5/202517/6/2026
Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.
AplazadaMedia (4.3)0.15%—Ability INC WEB Accessibility With MAX AccessAI7/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar allows Cross Site Request Forgery.This issue affects Web Accessibility with Max Access: from n/a through <= 2.0.9.
AplazadaAlta (7.1)0.14%—Offshorewebmaster Availability CalendarAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calendar: from n/a through <= 0.2.4.
AplazadaAlta (8.5)0.49%—Ability INC Accessibility SuiteAI11/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ability, Inc Accessibility Suite online-accessibility allows SQL Injection.This issue affects Accessibility Suite: from n/a through <= 4.18.
AplazadaMedia (6.5)0.22%—Ability INC Accessibility SuiteAI10/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Stored XSS.This issue affects Accessibility Suite: from n/a through <= 4.18.
AplazadaMedia (6.4)0.24%—Vulnerability-lookupAI8/4/202517/6/2026
Vulnerability-Lookup before 2.7.1 allows stored XSS via a user bio in website/web/views/user.py.
ModificadaAlta (7.7)0.39%—Netapp Active IQ Unified ManagerNetapp Manageability Software Development KITNetapp OntapNetapp Solidfire & HCI Management Node+718/2/202517/6/2026
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
ModificadaCrítica (9.8)1.2%—Xmlsoft Libxml2Netapp HCI Compute NodeNetapp H410c FirmwareNetapp H300s Firmware+718/2/202517/6/2026
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.