Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.80% | — | HP Command CenterHP Omen Gaming HUB | 12/12/2022 | 17/6/2026 | A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege and/or denial of service. HP has released software updates to mitigate the potential vulnerability. | |
| Modificada | Crítica (9.1) | 0.91% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 10/5/2022 | 17/6/2026 | The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an… | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+26 | 28/1/2022 | 15/8/2026 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends… | |
| Modificada | Alta (8.8) | 1.1% | — | Starwindsoftware Command Center | 24/1/2022 | 17/6/2026 | A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects StarWind Command Center build 6003 v2. | |
| Modificada | Crítica (9.8) | 1.2% | — | Starwind Command CenterStarwind San&nas | 4/1/2022 | 17/6/2026 | A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus could escalate privileges. This affects StarWind SAN and NAS build 1578 and StarWind Command Center build 6864. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Alienware Command Center ApplicationDell Command | UpdateDell Update/alienware Update | 9/8/2021 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbitrary code on the system. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | NCR Command Center Agent | 7/2/2021 | 17/6/2026 | CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position… | |
| Modificada | Media (5.5) | 0.35% | — | Linux KernelDebian LinuxStarwindsoftware Command CenterStarwindsoftware Starwind Hyperconverged Appliance+2 | 2/12/2020 | 17/6/2026 | A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service. | |
| Modificada | Alta (8.8) | 1.7% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 30/6/2020 | 17/6/2026 | The MFT admin service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server contains a vulnerability that theoretically allows an authenticated user with specific permissions to obtain the session identifier of another user. The session identifier… | |
| Modificada | Crítica (9.6) | 1.3% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 30/6/2020 | 17/6/2026 | The MFT Browser file transfer client and MFT Browser admin client components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server contain a vulnerability that theoretically allows an attacker to craft an URL that will execute arbitrary commands on the… | |
| Modificada | Media (5.3) | 0.49% | — | VIMDebian LinuxOpensuse LeapCanonical Ubuntu Linux+3 | 28/5/2020 | 17/6/2026 | In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua). | |
| Modificada | Alta (8.8) | 2.5% | — | Kyocera Command Center RX | 6/6/2019 | 17/6/2026 | Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a cleartext FTP or SMB password. | |
| Modificada | Crítica (9.9) | 1.2% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 11/12/2018 | 17/6/2026 | The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Managed File Transfer Internet Server contains vulnerabilities where an authenticated user with specific privileges can gain access to credentials to other systems. Affected releases are TIBCO Software… | |
| Modificada | Alta (7.5) | 2.1% | — | Pivotal Software Greenplum Command Center | 11/5/2018 | 17/6/2026 | Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database contents. | |
| Modificada | Alta (8.8) | 1.3% | — | Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 17/10/2017 | 17/6/2026 | Deployments of TIBCO Managed File Transfer Command Center versions 8.0.0 and 8.0.1 and TIBCO Managed File Transfer Internet Server versions 8.0.0 and 8.0.1 that enable the Administrator Service may be affected by a vulnerability which may allow any authenticated user to gain administrative control of Managed File… | |
| Modificada | Alta (8.1) | 2.1% | — | Citrix Command Center | 14/4/2016 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.61% | — | HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+3 | 4/11/2015 | 17/6/2026 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. | |
| Modificada | Media (4) | 2.3% | — | Tibco Managed File Transfer Internet ServerTibco VaultTibco Managed File Transfer Command CenterTibco Slingshot | 29/9/2015 | 17/6/2026 | TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot before 1.9.4, and Vault before 2.0.1 allow remote authenticated users to obtain sensitive information via a crafted HTTP request. | |
| Modificada | Alta (7.5) | 5.2% | — | Citrix Command Center | 26/3/2015 | 17/6/2026 | Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Citrix Command Center | 26/3/2015 | 17/6/2026 | Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml. | |
| Modificada | Media (6.4) | 1.1% | — | Tibco Managed File Transfer Internet ServerTibco Managed File Transfer Command CenterTibco SlingshotTibco Vault | 21/11/2014 | 17/6/2026 | TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before 1.1.1 allow remote attackers to obtain sensitive information or modify data by leveraging agent access. | |
| Modificada | Media (5) | 1.8% | — | Tibco SlingshotTibco VaultTibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server | 30/4/2014 | 17/6/2026 | TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1 allow remote attackers to obtain sensitive information via a crafted HTTP request. | |
| Modificada | Media (4.3) | 0.98% | — | IBM Cognos Command Center | 14/12/2013 | 16/6/2026 | Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie. | |
| Modificada | Media (6.8) | 0.57% | — | IBM Cognos Command Center | 14/12/2013 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services. | |
| Modificada | Baja (3.5) | 0.95% | — | IBM Star Command Center | 25/7/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Web\Content\Help\ in the Web Client in IBM Cognos Command Center (aka Star Command Center or Star Analytics) before 10.1, when Internet Explorer is used, allow remote authenticated users to inject arbitrary web script or HTML via unspecified… |