Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

2615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Deltaww Infrasuite Device Master27/3/202317/6/2026
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.
ModificadaAlta (8.8)1.6%—Deltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution.
ModificadaCrítica (9.8)1.1%—Deltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.
ModificadaAlta (8.8)1.3%—Deltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
ModificadaAlta (7.5)0.57%—Deltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.
ModificadaAlta (8.8)0.55%—Deltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.
ModificadaAlta (7.5)0.74%—Deltaww Infrasuite Device Master27/3/202317/6/2026
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.
ModificadaAlta (7.8)0.16%—Deltaww Infrasuite Device Master27/3/202317/6/2026
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.
ModificadaAlta (8.8)0.66%—Deltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.
ModificadaCrítica (9.8)50%💥 ExploitDeltaww Infrasuite Device Master27/3/202317/6/2026
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary…
ModificadaMedia (5.4)0.49%—IBM Maximo Application SuiteIBM Maximo Asset Management2/3/202317/6/2026
IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within…
ModificadaAlta (8.8)26%—Salesagility Suitecrm25/2/202317/6/2026
Path traversal: '\..\filename' en el repositorio salesagility/suitecrm de GitHub anterior a 7.12.9.
ModificadaMedia (5.5)0.19%—IBM Maximo Application Suite24/2/202317/6/2026
IBM Maximo Application Suite 8.8.0 y 8.9.0 almacena información potencialmente confidencial que podría ser leída por un usuario local. ID de IBM X-Force: 241584.
ModificadaAlta (7.8)0.18%—Dell Multifunction Printer E525w Driver AND Software Suite21/2/202317/6/2026
Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system
ModificadaAlta (7.5)0.50%—IBM Maximo Application SuiteIBM Maximo Asset Management17/2/202317/6/2026
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 237587.
ModificadaBaja (3.3)0.17%—Dell Command | Integration Suite FOR System Center13/2/202317/6/2026
Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.
ModificadaMedia (4.9)0.55%—Dell Wyse Management Suite11/2/202317/6/2026
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
ModificadaMedia (6.5)0.51%—Dell Wyse Management Suite11/2/202317/6/2026
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities.
ModificadaMedia (4.9)0.55%—Dell Wyse Management Suite11/2/202317/6/2026
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
ModificadaMedia (4.9)0.55%—Dell Wyse Management Suite11/2/202317/6/2026
Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.
ModificadaMedia (4.9)0.55%—Dell Wyse Management Suite11/2/202317/6/2026
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users under administration and unassigned admins for which the group admin is not authorized.
ModificadaMedia (5.3)0.47%—Dell Wyse Management Suite11/2/202317/6/2026
Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research.
ModificadaMedia (6.1)0.62%—Jsuites31/1/202317/6/2026
Las versiones del paquete jsuites anteriores a la 5.0.1 son vulnerables a Cross-site Scripting (XSS) debido a una sanitización inadecuada de la entrada del usuario en la función Editor().
ModificadaAlta (8.8)0.99%—Deltaww Infrasuite Device Master26/1/202317/6/2026
Existe una vulnerabilidad de escalada de privilegios en Delta Electronics InfraSuite Device Master 00.00.02a. Un usuario predeterminado 'Usuario', que está en el grupo 'Usuario de solo lectura', puede ver la contraseña de otro usuario predeterminado 'Administrador', que está en el grupo 'Administrador'. Esto permite…
ModificadaAlta (7.5)0.63%—Oracle E-business Suite18/1/202317/6/2026
Vulnerabilidad en el producto Oracle Applications DBA de Oracle E-Business Suite (componente: Java utils). Las versiones compatibles que se ven afectadas son 12.2.3-12.2.12. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red a través de HTTP comprometer el DBA de…