Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.89% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection. | |
| Modificada | Crítica (9.8) | 1.5% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector. | |
| Modificada | Alta (7.5) | 1.2% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different customer tenant. | |
| Modificada | Alta (8.4) | 0.36% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials. | |
| Modificada | Alta (8.8) | 1.2% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from the web UI into the database. | |
| Modificada | Alta (8.4) | 0.36% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system. | |
| Modificada | Alta (8.8) | 2.3% | — | Zingbox Inspector | 9/10/2019 | 17/6/2026 | A command injection vulnerability exists in the Zingbox Inspector versions 1.286 and earlier, that allows for an authenticated user to execute arbitrary system commands in the CLI. | |
| Modificada | Crítica (9.1) | 2.5% | — | Openstack Ironic-inspectorRedhat Openstack | 30/7/2019 | 17/6/2026 | A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a… | |
| Modificada | Media (5.4) | 0.81% | 💥 PoC | Trendmicro Deep Discovery Inspector | 28/9/2018 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability. | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Modificada | Alta (7.5) | 2.5% | — | Trendmicro Deep Discovery Email Inspector | 3/8/2017 | 17/6/2026 | Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable installations, thus disabling the service. Formerly ZDI-CAN-4350. | |
| Modificada | Alta (7.3) | 0.97% | — | Intel AdvisorCryptography FOR Intel Integrated Performance PrimitivesIntel Data Analytics Acceleration LibraryIntel Inspector+8 | 28/2/2017 | 17/6/2026 | Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel… | |
| Modificada | Alta (7.2) | 7.8% | 💥 Exploit | Trend Micro Deep Discovery Inspector | 30/6/2016 | 17/6/2026 | hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header. | |
| Modificada | Media (6.8) | 1.6% | — | Openstack Ironic Inspector | 25/11/2015 | 17/6/2026 | OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error. | |
| Modificada | Media (5.5) | 2.7% | — | Trendmicro Deep Discovery Inspector | 23/8/2015 | 17/6/2026 | Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information or change the configuration via a direct request to the (1)… | |
| Modificada | Media (4.3) | 2.7% | — | Trendmicro Deep Discovery Inspector | 23/8/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allow remote attackers to inject arbitrary web script or HTML via… | |
| Modificada | Media (4) | 7.9% | 💥 Exploit | HP Webinspect | 7/6/2015 | 17/6/2026 | Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restrictions via unknown vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Inspector IT Wiz-ad | 5/12/2008 | 16/6/2026 | SQL injection vulnerability in Wiz-Ad 1.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Mg-soft NET Inspector | 20/3/2008 | 16/6/2026 | Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to execute arbitrary code via format string specifiers in the URI, which is recorded in a log file. | |
| Modificada | Alta (7.1) | 2.6% | 💥 Exploit | Mg-soft NET Inspector | 20/3/2008 | 16/6/2026 | MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (exception and crash) via a UDP packet to the SNMP Trap Service (MgWTrap3.exe) or (2) denial of service (device freeze or memory consumption) via a malformed request to the Net Inspector Server (niengine). | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Mg-soft NET Inspector | 20/3/2008 | 16/6/2026 | Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot dot slash) in the URI. | |
| Modificada | Media (5) | 1.6% | — | SPI Dynamics Webinspect | 3/8/2005 | 16/6/2026 | Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Javascript from one application into another. | |
| Modificada | Media (5) | 8.3% | 💥 Exploit | Elron IM Anti VirusElron IM Message Inspector | 22/8/2001 | 16/6/2026 | Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL. |