Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.3%—Byzoro Smart S85f Management Platform26/8/202317/6/2026
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /sysmanage/licence.php. The manipulation leads to improper access controls. The exploit has been disclosed to the public and may…
ModificadaMedia (4.3)1.2%—Byzoro Smart S85f Management Platform26/8/202317/6/2026
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230809. It has been rated as problematic. This issue affects some unknown processing of the file /config/php.ini. The manipulation leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public and…
ModificadaMedia (4.8)0.41%—Secnet Annet AC Centralized Management Platform29/6/202317/6/2026
Annet AC Centralized Management Platform 1.02.040 is vulnerable to Stored Cross-Site Scripting (XSS) .
ModificadaMedia (4.8)0.39%—AC Centralized Management Platform Project AC Centralized Management Platform12/6/202317/6/2026
A Cross Site Scripting (XSS) vulnerability in Youxun Electronic Equipment (Shanghai) Co., Ltd AC Centralized Management Platform v1.02.040 allows attackers to execute arbitrary code via uploading a crafted HTML file to the interface /upfile.cgi.
ModificadaCrítica (9.8)0.69%—Private Cloud Management Platform Project Private Cloud Management Platform5/8/202217/6/2026
A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It is possible to launch the attack…
ModificadaCrítica (9.8)1.1%—Rainier Open Virtual Simulation Experiment Teaching Management Platform5/5/202217/6/2026
Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server.
ModificadaMedia (6.5)0.52%—Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+118/2/202217/6/2026
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 uses the MD5 algorithm to hash the passwords before storing them but does not salt the hash. As a result, attackers may be able to crack the hashed passwords.
ModificadaCrítica (9.8)1.4%—Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+118/2/202217/6/2026
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server into accessing routes on those…
ModificadaCrítica (9.8)3.7%—Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+118/2/202217/6/2026
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution,…
ModificadaAlta (7.5)1.1%—Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+118/2/202217/6/2026
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input, which may allow an attacker to perform a SQL injection and obtain sensitive information.
ModificadaCrítica (9.8)1.2%—Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+118/2/202217/6/2026
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inject arbitrary commands.
ModificadaCrítica (9.8)3.2%—Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+118/2/202217/6/2026
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain access to these functions and achieve remote code execution, create a…
ModificadaAlta (7.5)0.99%—Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+118/2/202217/6/2026
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has a deserialization function that does not validate or check the data, allowing arbitrary classes to be created.
ModificadaAlta (8.8)1.3%—IBM Emptoris Spend AnalysisIBM Emptoris Strategic Supply Management Platform20/2/202017/6/2026
IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM…
ModificadaAlta (8.8)2.2%—Verint Collaboration ComplianceVerint Quality Management Platform4/10/201817/6/2026
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.
ModificadaMedia (6.5)1.8%—Verint Verba Collaboration Compliance AND Quality Management Platform4/10/201817/6/2026
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.
ModificadaCrítica (9.8)2.2%—Redhat 3scale API Management Platform7/7/201717/6/2026
Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted APIs. NOTE: some sources have a typo in which CVE-2017-7512 maps to an OpenVPN…
ModificadaMedia (4.6)0.22%—Symantec Management Platform10/10/201316/6/2026
The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' installations, which makes it easier for local users to obtain sensitive information about…
ModificadaMedia (6.8)43%—Symantec Altiris Deployment SolutionSymantec Altiris Notification ServerSymantec Management Platform7/3/201116/6/2026
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute…
ModificadaAlta (9.3)40%—Symantec Altiris Deployment SolutionSymantec Altiris Management PlatformSymantec Altiris Notification Server25/11/200916/6/2026
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long…
ModificadaAlta (9.3)45%—Symantec Altiris Deployment SolutionSymantec Altiris Management PlatformSymantec Altiris Notification Server3/11/200916/6/2026
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec…