Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.2% | — | BMC Bladelogic Server Automation Console | 13/12/2016 | 17/6/2026 | BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process. | |
| Modificada | Media (6.1) | 0.95% | — | Bosch Bladecontrol-webvis | 6/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.4) | 0.88% | — | Bosch Bladecontrol-webvis | 6/7/2016 | 17/6/2026 | SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | BMC Bladelogic Server Automation Console | 13/6/2016 | 17/6/2026 | The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure. | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | BMC Bladelogic Server Automation Console | 13/6/2016 | 17/6/2026 | The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure. | |
| Modificada | Media (4.9) | 0.41% | — | Cisco UCS B-series Blade Server Software | 12/10/2015 | 17/6/2026 | Cisco Unified Computing System (UCS) B Blade Server Software 2.2.x before 2.2.6 allows local users to cause a denial of service (host OS or BMC hang) by sending crafted packets over the Inter-IC (I2C) bus, aka Bug ID CSCuq77241. | |
| Modificada | Alta (10) | 6.1% | — | Alliedtelesis Centrecom Ar415s FirmwareAlliedtelesis Centrecom Ar415sAlliedtelesis At-8624t/2m FirmwareAlliedtelesis At-8624t/2m+44 | 19/12/2014 | 17/6/2026 | Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT-9816GB, AT-9924T, AT-9924Ts, CentreCOM AR415S, CentreCOM AR450S, CentreCOM AR550S, CentreCOM AR570S, CentreCOM 8700SL, CentreCOM 8948XL, CentreCOM 9924SP, CentreCOM… | |
| Modificada | Alta (10) | 2.0% | — | IBM System Networking Rackswitch G8332 FirmwareIBM System Networking Rackswitch G8332IBM Bladecenter 1G FirmwareIBM Bladecenter 1G+36 | 23/9/2014 | 17/6/2026 | IBM System Networking G8052, G8124, G8124-E, G8124-ER, G8264, G8316, and G8264-T switches before 7.9.10.0; EN4093, EN4093R, CN4093, SI4093, EN2092, and G8264CS switches before 7.8.6.0; Flex System Interconnect Fabric before 7.8.6.0; 1G L2-7 SLB switch for Bladecenter before 21.0.21.0; 10G VFSM for Bladecenter before… | |
| Modificada | Alta (7.8) | 2.5% | — | H3C SecbladefwH3C Secpath1000feH3C F1000-e VPN FirewallH3C S5820 Secblade VPN Firewall Module+13 | 28/7/2014 | 16/6/2026 | Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 0.95% | — | IBM Integrated Management Module 2IBM BladecenterIBM Flex System Manager Node 7955IBM Flex System Manager Node 8731+27 | 21/1/2014 | 16/6/2026 | Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic. | |
| Modificada | Media (4) | 0.78% | — | IBM BladecenterIBM Flex System X220 Compute NodeIBM Flex System X240 Compute NodeIBM Flex System X440 Compute Node+26 | 9/8/2013 | 16/6/2026 | The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information by reading a file. | |
| Modificada | Media (4.3) | 0.95% | — | IBM BladecenterIBM Flex System X220 Compute NodeIBM Flex System X240 Compute NodeIBM Flex System X440 Compute Node+26 | 9/8/2013 | 16/6/2026 | The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for… | |
| Modificada | Alta (10) | 2.0% | — | IBM BladecenterIBM Flex System X220 Compute NodeIBM Flex System X240 Compute NodeIBM Flex System X440 Compute Node+26 | 9/8/2013 | 16/6/2026 | The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers… | |
| Modificada | Baja (2.1) | 0.40% | — | Oracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Sparc T3-1Oracle Sparc T3-1b+15 | 18/10/2011 | 16/6/2026 | Unspecified vulnerability in SysFW 8.0 on certain SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade based servers allows local users to affect confidentiality, related to Integrated Lights Out Manager CLI. | |
| Modificada | Alta (7.5) | 1.4% | — | Oracle SysfwOracle Netra Sparc T3-1Oracle Netra Sparc T3-1bOracle Sparc T3-1+8 | 21/7/2011 | 16/6/2026 | Unspecified vulnerability in Oracle SysFW 8.1.0.a in various Oracle SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade servers allows remote attackers to affect confidentiality, integrity, and availability, related to Sun Integrated Lights Out Manager (ILOM). | |
| Modificada | Baja (2.1) | 0.33% | — | Oracle SysfwOracle Netra Sparc T3-1Oracle Sparc T3-1Oracle Sparc T3-1b+19 | 20/7/2011 | 16/6/2026 | Unspecified vulnerability in Sun Integrated Lights Out Manager in Oracle SysFW 8.0.3.b or earlier for various Oracle SPARC T3, SPARC Netra T3, Sun Blade, and Sun Fire servers allows local users to affect confidentiality via unknown vectors. | |
| Modificada | Alta (7.8) | 2.7% | — | NEC BladesystemcenterNEC ExpresssystemcenterNEC SigmasystemcenterNEC Virtualpccenter+1 | 19/5/2010 | 16/6/2026 | Unspecified vulnerability in NEC WebSAM DeploymentManager 5.13 and earlier, as used in SigmaSystemCenter 2.1 Update2 and earlier, BladeSystemCenter, ExpressSystemCenter, and VirtualPCCenter 2.2 and earlier, allows remote attackers to cause a denial of service (OS shutdown or restart) via unknown vectors related to… | |
| Modificada | Media (4) | 1.1% | — | IBM Advanced Management ModuleIBM Bladecenter | 13/4/2009 | 16/6/2026 | private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | IBM Advanced Management ModuleIBM Bladecenter | 13/4/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi… | |
| Modificada | Media (4.6) | 0.31% | — | SUN Blade T6300 ServerSUN Blade T6320 ServerSUN Fire Enterprise Server T1000SUN Fire Enterprise Server T2000+9 | 7/11/2008 | 16/6/2026 | The SPARC hypervisor in Sun System Firmware 6.6.3 through 6.6.5 and 7.1.3 through 7.1.3.e on UltraSPARC T1, T2, and T2+ processors allows logical domain users to access memory in other logical domains via unknown vectors. | |
| Modificada | Alta (9) | 2.0% | — | SUN Integrated Lights-out ManagerSUN Blade 6000 Modular System With ChassisSUN Blade 6048 Modular System With ChassisSUN Blade 8000 Modular System+33 | 23/10/2008 | 16/6/2026 | Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors. | |
| Modificada | Alta (7.1) | 32% | 💥 PoC | BSDBsdi BSD OSCisco IOSDragonflybsd+15 | 20/10/2008 | 16/6/2026 | The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as… | |
| Modificada | Media (5) | 1.6% | — | Hitachi Jp1-cm2-network Node ManagerHitachi Jp1-cm2-network Node Manager 250Hitachi JPI Automatic JOB Management System 2Hitachi JPI Performance Management+5 | 27/4/2006 | 16/6/2026 | Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data. | |
| Modificada | Alta (7.5) | 3.4% | — | Bladeenc | 19/2/2003 | 16/6/2026 | Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | IBM Informix WEB Datablade | 3/7/2002 | 16/6/2026 | webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request. |