Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.25% | — | Redhat Satellite | 2/6/2021 | 17/6/2026 | A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows an attacker to gain control of DHCP records from the network. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (6.5) | 0.77% | — | Redhat SatelliteRedhat Satellite CapsuleTheforeman Foreman Ansible | 27/5/2021 | 17/6/2026 | A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This flaw affects tfm-rubygem-foreman_ansible… | |
| Modificada | Media (6.3) | 0.65% | — | Theforeman Foreman AzurermRedhat Satellite | 8/4/2021 | 17/6/2026 | A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system… | |
| Modificada | Media (5.3) | 0.26% | — | Redhat Satellite | 23/2/2021 | 17/6/2026 | A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | |
| Modificada | Alta (8.8) | 2.0% | — | Netgear Cbk40 FirmwareNetgear Cbk43 FirmwareNetgear Cbr40 FirmwareNetgear Ex6200 Firmware+35 | 12/2/2021 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name option in a DHCP request can trigger… | |
| Modificada | Crítica (9.8) | 4.3% | — | Cisco Smart Software Manager Satellite | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.8) | 4.0% | — | Cisco Smart Software Manager Satellite | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 4.4% | — | Cisco Smart Software Manager Satellite | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.8) | 4.0% | — | Cisco Smart Software Manager Satellite | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 4.4% | — | Cisco Smart Software Manager Satellite | 20/1/2021 | 17/6/2026 | Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (8.8) | 0.32% | — | Redhat Satellite | 31/7/2020 | 17/6/2026 | A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance. | |
| Modificada | Media (5.3) | 2.4% | — | Redhat Hibernate ValidatorIBM Websphere Application ServerRedhat Jboss Enterprise Application PlatformRedhat Satellite+3 | 6/5/2020 | 17/6/2026 | A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling… | |
| Modificada | Alta (7.5) | 2.2% | — | NokogiriRedhat Cloudforms Management EngineRedhat OpenshiftRedhat Openstack+4 | 19/2/2020 | 16/6/2026 | Nokogiri before 1.5.4 is vulnerable to XXE attacks | |
| Modificada | Media (6.5) | 0.52% | — | Redhat Satellite | 2/1/2020 | 17/6/2026 | Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content. | |
| Modificada | Media (5.5) | 0.31% | — | Theforeman Hammer CLIRedhat Satellite | 13/12/2019 | 17/6/2026 | rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable | |
| Modificada | Media (5.4) | 0.55% | — | Theforeman KatelloRedhat Satellite | 3/12/2019 | 16/6/2026 | Katello has multiple XSS issues in various entities | |
| Modificada | Media (6.5) | 1.0% | — | Redhat Satellite | 2/12/2019 | 16/6/2026 | A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties. | |
| Modificada | Media (6.5) | 2.2% | — | NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+3 | 5/11/2019 | 17/6/2026 | Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits | |
| Modificada | Media (6.5) | 2.1% | — | NokogiriDebian LinuxRedhat Cloudforms Management EngineRedhat Openstack+3 | 5/11/2019 | 17/6/2026 | Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents | |
| Modificada | Crítica (9.1) | 2.1% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+3 | 17/10/2019 | 17/6/2026 | From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks. | |
| Modificada | Media (4.7) | 2.6% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require… | |
| Modificada | Media (4.2) | 2.2% | — | Oracle JDKOracle JRENetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+10 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u221; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java… | |
| Modificada | Baja (3.7) | 3.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.3% | — | Oracle JDKOracle JRENetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… |