Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Lenovo Xclarity Administrator | 14/2/2020 | 17/6/2026 | An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes. | |
| Modificada | Media (5.4) | 0.52% | — | Lenovo Xclarity Administrator | 14/2/2020 | 17/6/2026 | An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code… | |
| Modificada | Alta (8.8) | 14% | 💥 Exploit | Kaseya Virtual System Administrator | 13/2/2020 | 17/6/2026 | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient restrictions in file paths to json.ashx. | |
| Modificada | Media (4.9) | 0.65% | — | Lenovo Xclarity Administrator | 3/9/2019 | 17/6/2026 | A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on… | |
| Modificada | Media (6.1) | 0.82% | — | Lenovo Xclarity Administrator | 3/9/2019 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the user's web browser. The JavaScript code is not executed on LXCA itself. | |
| Modificada | Media (4.8) | 0.65% | — | Lenovo Xclarity Administrator | 3/9/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the user's web browser. The JavaScript code is not executed on LXCA itself. | |
| Modificada | Alta (7.5) | 1.4% | — | Lenovo Xclarity AdministratorLenovo Xclarity Integrator | 3/9/2019 | 17/6/2026 | An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow… | |
| Modificada | Alta (7.5) | 1.8% | — | Kaseya Virtual System Administrator | 26/8/2019 | 17/6/2026 | An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send properly formatted requests to the web application and download sensitive files and information. For example, the /DATAREPORTS directory… | |
| Modificada | Crítica (9.8) | 23% | 💥 Exploit | Computerlab Maple Computer WBT Snmp Administrator | 17/7/2019 | 17/6/2026 | SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987. | |
| Modificada | Alta (7.8) | 0.90% | 💥 PoC | Siemens TIA AdministratorSiemens Sinetplan | 11/7/2019 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administrator) allows to execute certain application commands without proper authentication. The vulnerability could be exploited by an attacker with local access to the affected… | |
| Modificada | Crítica (9.1) | 1.8% | — | Dell EMC Openmanage Server Administrator | 6/6/2019 | 17/6/2026 | Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any… | |
| Modificada | Alta (7.5) | 3.8% | — | Dell EMC Openmanage Server Administrator | 6/6/2019 | 17/6/2026 | Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type… | |
| Modificada | Media (5.9) | 1.5% | — | Lenovo Xclarity Administrator | 3/5/2019 | 17/6/2026 | An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA versions 2.0.0 to 2.3.x. | |
| Modificada | Alta (7.5) | 2.6% | — | Dell EMC Openmanage Server Administrator | 25/4/2019 | 17/6/2026 | Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with overlapping ranges to cause the application to compress each of the requested bytes, resulting in a crash due to excessive… | |
| Modificada | Media (4.9) | 3.5% | — | Dell EMC Openmanage Server Administrator | 25/4/2019 | 17/6/2026 | Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exploit this vulnerability to gain unauthorized access to the file system by exploiting insufficient sanitization of input… | |
| Analizada | Crítica (9.8) | 29% | ⚠ Explotación activa | Kaseya Virtual System Administrator | 5/2/2019 | 13/8/2026 | Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild. | |
| Modificada | Alta (8.8) | 2.2% | — | Lenovo Xclarity Administrator | 30/7/2018 | 17/6/2026 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system. | |
| Modificada | Alta (7.5) | 0.46% | — | Lenovo Xclarity Administrator | 30/7/2018 | 17/6/2026 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those… | |
| Modificada | Alta (8.8) | 0.96% | — | Lenovo Xclarity Administrator | 30/7/2018 | 17/6/2026 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user. | |
| Modificada | Media (6.5) | 1.4% | — | Tibco Administrator | 13/6/2018 | 17/6/2026 | The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected… | |
| Modificada | Media (5.4) | 0.86% | — | Tibco Administrator | 13/6/2018 | 17/6/2026 | The TIBCO Administrator server component of of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains multiple vulnerabilities wherein a malicious user could theoretically perform cross-site scripting (XSS) attacks by way of manipulating… | |
| Modificada | Crítica (9.8) | 3.8% | — | OpenslpDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+34 | 23/4/2018 | 17/6/2026 | OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability. | |
| Modificada | Alta (7.4) | 0.25% | — | Kaseya Virtual System Administrator | 26/3/2018 | 17/6/2026 | It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working and/or temporary folders. Successful exploitation results in the execution of arbitrary programs with… | |
| Modificada | Media (6.5) | 1.4% | — | HP Moonshot Remote Console AdministratorHP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware | 15/2/2018 | 17/6/2026 | A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | HP Smart Storage Administrator | 15/2/2018 | 17/6/2026 | A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found. |