Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 1.3% | — | Cisco Integrated Management Controller Supervisor | 7/6/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the… | |
| Modificada | Media (5.3) | 0.34% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability. | |
| Modificada | Media (5.3) | 0.34% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability. | |
| Modificada | Media (5.3) | 0.34% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, use after free vulnerabilities can be exploited when CX Supervisor parses a specially crafted project file. | |
| Modificada | Media (5.3) | 0.36% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow. | |
| Modificada | Media (5.3) | 0.34% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability. | |
| Modificada | Media (5.3) | 0.29% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets. | |
| Modificada | Media (5.3) | 0.36% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow. | |
| Modificada | Alta (8.8) | 87% | — | Supervisord SupervisorFedoraproject FedoraDebian LinuxRedhat Cloudforms | 23/8/2017 | 17/6/2026 | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups. | |
| Modificada | Alta (8.8) | 2.6% | — | Cisco Integrated Management Controller Supervisor | 20/4/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize user-supplied HTTP input. An attacker… | |
| Modificada | Media (5.4) | 0.93% | — | Cisco Integrated Management Controller Supervisor | 20/4/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this… | |
| Modificada | Media (5.4) | 0.97% | — | Cisco Integrated Management Controller Supervisor | 20/4/2017 | 17/6/2026 | A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not… | |
| Modificada | Alta (8.8) | 4.2% | — | Cisco Integrated Management Controller Supervisor | 20/4/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of… | |
| Modificada | Media (6.8) | 2.2% | — | Cisco Integrated Management Controller Supervisor | 15/12/2015 | 17/6/2026 | The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286. | |
| Modificada | Media (6.8) | 1.1% | — | EMC Sourceone Email Supervisor | 18/10/2015 | 17/6/2026 | EMC SourceOne Email Supervisor before 7.2 uses hardcoded encryption keys, which makes it easier for attackers to obtain access by examining how a program's code conducts cryptographic operations. | |
| Modificada | Alta (7.5) | 3.5% | — | EMC Sourceone Email Supervisor | 18/10/2015 | 17/6/2026 | EMC SourceOne Email Supervisor before 7.2 does not properly employ random values for session IDs, which makes it easier for remote attackers to obtain access by guessing an ID. | |
| Modificada | Media (4.3) | 2.3% | — | EMC Sourceone Email Supervisor | 18/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Reviewer in EMC SourceOne Email Supervisor before 7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.9% | — | EMC Sourceone Email Supervisor | 18/10/2015 | 17/6/2026 | Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to obtain access via a brute-force approach. | |
| Modificada | Alta (9.4) | 2.8% | — | Cisco Integrated Management Controller SupervisorCisco Unified Computing System Director | 4/9/2015 | 17/6/2026 | The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625. | |
| Modificada | Alta (9) | 2.9% | — | Cisco Telepresence Advanced Media GatewayCisco Telepresence IP GatewayCisco Telepresence IP VCR 1.0 ConverterCisco Telepresence IP VCR 2.4+6 | 25/5/2015 | 17/6/2026 | The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5… | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Telepresence Supervisor MSE 8050 SoftwareCisco Telepresence Supervisor MSE 8050 | 16/5/2013 | 16/6/2026 | Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing TCP connections at a high rate, aka Bug IDs CSCuf76076 and CSCuf79763. | |
| Modificada | Media (5) | 1.1% | — | IBM Remote Supervisor Adapter II Firmware | 25/9/2012 | 16/6/2026 | IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Alta (7.1) | 1.9% | — | Cisco Route Switch ProcessorCisco Supervisor Engine | 27/3/2008 | 16/6/2026 | Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device… | |
| Modificada | Media (5) | 1.9% | — | Cisco Catalyst 12xx Supervisor SoftwareCisco Catalyst 29xx Supervisor SoftwareCisco Catalyst 5xxx Supervisor Software | 1/3/1999 | 16/6/2026 | Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload. |