Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

5404 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.35%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes15/10/202517/6/2026
When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (7.1)0.31%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes15/10/202517/6/2026
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6)0.31%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes15/10/202517/6/2026
When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.35%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Policy Enforcement Manager15/10/202517/6/2026
When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.44%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+1915/10/202517/6/2026
When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.43%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+1915/10/202517/6/2026
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaMedia (6)0.26%—Lenovo LecloudAI15/10/20258/10/2026
Se reportó una vulnerabilidad en la aplicación cliente Lenovo LeCloud que, bajo ciertas condiciones, podría permitir la revelación de información.
AplazadaAlta (8.7)0.46%—Huijietong Cloud Video PlatformAI15/10/20251/10/2026
La Plataforma de Video en la Nube Huijietong contiene una vulnerabilidad de salto de ruta que permite a un atacante no autenticado suministrar rutas de archivo arbitrarias al parámetro 'fullPath' del endpoint '/fileDownload?action=downloadBackupFile' y recuperar archivos del sistema de archivos del servidor. VulnCheck…
ModificadaAlta (7.2)0.54%—Fortinet FortianalyzerFortinet Fortianalyzer CloudFortinet FortimanagerFortinet Fortimanager Cloud+214/10/202517/6/2026
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1…
ModificadaMedia (4.3)0.47%—Fortinet FortimailFortinet FortimanagerFortinet Fortimanager CloudFortinet Fortindr+814/10/202517/6/2026
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR…
AplazadaBaja (3)0.24%—SAP Cloud Appliance LibraryAISAP S/4hanaAI13/10/20258/10/2026
Las instancias de SAP Cloud Appliance Library permiten a un atacante con privilegios elevados explotar una configuración de perfil predeterminada insegura de S/4HANA en una instancia existente de SAP CAL para obtener acceso a otras instancias. Esto tiene un bajo impacto en la confidencialidad de la aplicación; la…
AplazadaMedia (5.3)0.43%—SAP Commerce CloudAI13/10/20258/10/2026
SAP Commerce Cloud contiene una vulnerabilidad de salto de ruta que puede permitir a los usuarios acceder a aplicaciones web como la Consola de Administración desde direcciones donde la Consola de Administración no está explícitamente desplegada. Esto podría potencialmente eludir las restricciones de acceso…
AnalizadaAlta (7.2)0.66%—Elastic Cloud Enterprise13/10/20258/10/2026
La neutralización indebida de elementos especiales utilizados en un motor de plantillas en Elastic Cloud Enterprise (ECE) puede permitir que un actor malicioso con acceso de administrador exfiltre información sensible y emita comandos mediante una cadena especialmente diseñada donde se evalúan las variables de Jinjava.
AplazadaAlta (8.6)0.58%—Ragic Enterprise Cloud DatabaseAI13/10/20258/10/2026
La Base de datos en la nube empresarial desarrollada por Ragic tiene una vulnerabilidad de carga de archivos arbitraria, lo que permite a atacantes remotos privilegiados cargar y ejecutar puertas traseras web shell, posibilitando así la ejecución de código arbitrario en el servidor.
AplazadaAlta (8.7)3.9%—Avtech Cloudsetup.cgiAI9/10/202517/6/2026
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can…
AplazadaCrítica (9.3)0.53%—Piriform CcleanerAIPiriform Ccleaner CloudAI8/10/202517/6/2026
CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry-point loader that diverts execution from __scrt_common_main_seh into a custom loader. That loader decodes an embedded blob into shellcode, allocates executable heap memory, resolves Windows API functions at runtime, and…
AplazadaMedia (4.7)0.24%—Logo Software INC Logo CloudAI6/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Software Inc. Logo Cloud allows Cross-Site Scripting (XSS). This issue affects Logo Cloud: before 1.18.
AplazadaMedia (5.5)0.16%—Logo Software INC Logo CloudAI6/10/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forceful Browsing. This issue affects Logo Cloud: before 2025.R6.
AplazadaMedia (4.3)0.19%—Logo Software INC Logo CloudAI6/10/202517/6/2026
Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affects Logo Cloud: before 2.57.
AplazadaMedia (6)0.29%—Logo Software INC Logo CloudAI6/10/202530/9/2026
Vulnerabilidad de omisión de autorización a través de clave controlada por el usuario en Logo Software Inc. Logo Cloud permite Navegación Forzada, Exposición de Fuga de Recursos. Este problema afecta a Logo Cloud: anterior a 0.67.
AnalizadaAlta (8.8)0.47%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an…
AnalizadaMedia (4.9)0.56%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the high-privilege capability `change_authentication`, could send multiple LDAP bind requests to a specific internal endpoint,…
AnalizadaMedia (6.5)0.30%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the…
AnalizadaMedia (5.4)0.36%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through the error messages and job inspection details of a saved…
AnalizadaMedia (5.4)0.36%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious payload through the `dataset.command` parameter of the…