Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.99% | — | Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+4 | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Media (6.7) | 0.19% | — | Vmware Aria OperationsVmware Cloud Foundation | 21/2/2024 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Analizada | Alta (7.8) | 0.15% | — | Microfocus Operations Agent | 15/2/2024 | 17/6/2026 | Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platforms. The vulnerability could allow local privilege escalation. | |
| Modificada | Media (4.8) | 38% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account. | |
| Modificada | Media (4.9) | 0.61% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information. | |
| Modificada | Alta (7.8) | 0.21% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access. | |
| Modificada | Media (4.8) | 0.50% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization. | |
| Modificada | Alta (7.8) | 0.25% | — | Vmware Aria Operations FOR Networks | 6/2/2024 | 17/6/2026 | Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system. | |
| Modificada | Media (5.3) | 0.57% | — | Honeywell Controledge Unit Operations Controller FirmwareHoneywell Controledge Virtual Unit Operations Controller Firmware | 31/1/2024 | 17/6/2026 | An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limited information from the device. Honeywell recommends updating to the most… | |
| Modificada | Alta (7.5) | 0.78% | — | Honeywell Controledge Unit Operations Controller FirmwareHoneywell Controledge Virtual Unit Operations Controller Firmware | 30/1/2024 | 17/6/2026 | An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in… | |
| Modificada | Media (6.5) | 1.4% | — | Microsoft System Center Operations Manager | 14/11/2023 | 17/6/2026 | Open Management Infrastructure Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 0.20% | — | Vmware Aria Operations FOR Logs | 20/10/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass. | |
| Modificada | Crítica (9.8) | 45% | 💥 PoC | Vmware Aria Operations FOR Logs | 20/10/2023 | 17/6/2026 | VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. | |
| Modificada | Alta (8.8) | 0.58% | — | Kubernetes Operations | 12/10/2023 | 17/6/2026 | Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode. | |
| Modificada | Media (6.7) | 0.19% | — | Vmware Aria OperationsVmware Cloud Foundation | 27/9/2023 | 17/6/2026 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Crítica (9.8) | 67% | 💥 Exploit | Vmware Aria Operations FOR Networks | 29/8/2023 | 17/6/2026 | Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI. | |
| Modificada | Alta (7.2) | 20% | — | Vmware Aria Operations FOR Networks | 29/8/2023 | 17/6/2026 | Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution. | |
| Modificada | Alta (8.8) | 0.90% | — | Veritas Infoscale Operations Manager | 17/7/2023 | 17/6/2026 | The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Vmware Aria Operations FOR Networks | 7/6/2023 | 17/6/2026 | Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution. | |
| Modificada | Media (6.7) | 0.22% | — | Vmware Aria OperationsVmware Cloud Foundation | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Media (6.7) | 0.18% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system. | |
| Modificada | Alta (7.2) | 1.0% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. | |
| Modificada | Alta (8.8) | 0.65% | — | Vmware Cloud FoundationVmware Vrealize Operations | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. | |
| Modificada | Crítica (9.8) | 0.58% | — | Veritas Infoscale Operations Manager | 10/5/2023 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the… | |
| Modificada | Alta (7.2) | 0.70% | — | Veritas Infoscale Operations Manager | 10/5/2023 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage… |