Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Dmparekh Wordpress Database Administrator | 16/1/2024 | 17/6/2026 | The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell EMC Openmanage Server Administrator | 13/10/2023 | 17/6/2026 | Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the system. Exploitation may lead to a complete system… | |
| Modificada | Media (5.5) | 0.18% | — | Hitachi OPS Center Administrator | 3/10/2023 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00. | |
| Modificada | Media (6.1) | 0.35% | — | Genesys Administrator Extension | 13/8/2023 | 17/6/2026 | Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261. | |
| Modificada | Alta (7.5) | 0.50% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Media (6.5) | 0.49% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. | |
| Modificada | Alta (7.2) | 1.3% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. | |
| Modificada | Alta (8.1) | 0.55% | — | Lenovo Xclarity Administrator | 26/6/2023 | 17/6/2026 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell Openmanage Server Administrator | 1/2/2023 | 17/6/2026 | Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with elevated privileges. Exploitation… | |
| Modificada | Media (4.9) | 0.76% | — | Microfocus Netiq Directory AND Resource Administrator | 28/9/2021 | 17/6/2026 | Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure. | |
| Modificada | Alta (8) | 0.68% | — | Tibco Administrator | 20/4/2021 | 17/6/2026 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator… | |
| Modificada | Alta (8.8) | 0.84% | — | Tibco Administrator | 20/4/2021 | 17/6/2026 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator… | |
| Modificada | Crítica (9.6) | 1.1% | — | Tibco AdministratorTibco Runtime Agent | 20/4/2021 | 17/6/2026 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator… | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Media (4.9) | 5.4% | 💥 PoC | Dell Openmanage Server Administrator | 2/3/2021 | 17/6/2026 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote user with admin privileges could potentially exploit this vulnerability to view arbitrary files on the target system by sending a specially crafted URL request. | |
| Modificada | Crítica (9.8) | 5.9% | — | Dell Openmanage Server Administrator | 2/3/2021 | 17/6/2026 | Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configuration contains an authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain admin access on the affected system. | |
| Modificada | Media (4.9) | 0.53% | — | Lenovo Xclarity Administrator | 10/2/2021 | 17/6/2026 | An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while… | |
| Modificada | Alta (7.8) | 1.4% | — | Schneider-electric Scadapack X70 Security Administrator | 16/9/2020 | 17/6/2026 | A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer. | |
| Modificada | Crítica (9.1) | 48% | 💥 Exploit | Dell EMC Openmanage Server Administrator | 28/7/2020 | 17/6/2026 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit these vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access… | |
| Modificada | Media (5.4) | 0.66% | — | HP Onboard Administrator | 23/4/2020 | 17/6/2026 | A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and mitigation information to resolve the vulnerability in HPE Onboard Administrator. * OA 4.95 (Linux… | |
| Modificada | Alta (7.2) | 15% | 💥 Exploit | Frozennode Laravel-administrator | 25/3/2020 | 17/6/2026 | FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued. | |
| Modificada | Media (6) | 0.31% | — | Lenovo Xclarity Administrator | 13/3/2020 | 17/6/2026 | An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when performing a Windows driver update. Affected logs are only accessible to… | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Kaseya Virtual System Administrator | 17/2/2020 | 17/6/2026 | Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2)… | |
| Modificada | Media (5.5) | 0.74% | — | Lenovo Xclarity Administrator | 14/2/2020 | 17/6/2026 | An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure. |