Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.84% | — | Hitachi Device ManagerHitachi Compute Systems ManagerHitachi Automation DirectorHitachi Tiered Storage Manager+4 | 14/2/2020 | 17/6/2026 | A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device… | |
| Modificada | Alta (7.5) | 3.6% | — | NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+2 | 27/1/2020 | 17/6/2026 | Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869. | |
| Modificada | Media (4.3) | 0.82% | — | Jenkins Health Advisor BY Cloudbees | 15/1/2020 | 17/6/2026 | A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient. | |
| Modificada | Alta (8.8) | 0.84% | — | Jenkins Health Advisor BY Cloudbees | 15/1/2020 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient. | |
| Modificada | Media (6.5) | 1.5% | — | Mcafee Webadvisor | 3/12/2019 | 17/6/2026 | API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a carefully crafted web site. | |
| Modificada | Media (6.5) | 0.94% | — | Mcafee Webadvisor | 3/12/2019 | 17/6/2026 | Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully crafted web site. | |
| Modificada | Alta (7.5) | 1.3% | — | Hitachi Device ManagerHitachi Replication ManagerHitachi Tiered Storage ManagerHitachi Infrastructure Analytics Advisor+1 | 12/11/2019 | 17/6/2026 | A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.7.0-00 allows an unauthenticated remote user to trigger a denial of service (DoS) condition because of Uncontrolled Resource Consumption. | |
| Modificada | Media (6.5) | 0.76% | — | IBM Qradar Advisor With Watson | 9/11/2019 | 17/6/2026 | IBM QRadar Advisor 1.0.0 through 2.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 166205. | |
| Modificada | Alta (7.5) | 11% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+14 | 30/7/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. | |
| Modificada | Crítica (9.8) | 5.2% | — | PythonRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+10 | 7/6/2019 | 17/6/2026 | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application… | |
| Modificada | Alta (7.5) | 1.7% | — | Brocade Network AdvisorNetapp Brocade Network Advisor | 22/1/2019 | 17/6/2026 | A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the… | |
| Modificada | Crítica (9.8) | 3.3% | — | Brocade Network AdvisorNetapp Brocade Network Advisor | 22/1/2019 | 17/6/2026 | A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited to execute arbitrary OS Commands. | |
| Modificada | Alta (8.1) | 7.4% | — | Brocade Network AdvisorNetapp Brocade Network Advisor | 22/1/2019 | 17/6/2026 | A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network… | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Qradar Advisor With Watson | 5/12/2018 | 17/6/2026 | IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147810. | |
| Modificada | Alta (8.1) | 2.1% | — | Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance | 10/8/2018 | 17/6/2026 | Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain… | |
| Modificada | Media (5.4) | 4.8% | — | Apache KafkaRedhat Jboss Middleware Text-only AdvisoriesOracle DatabaseOracle Primavera P6 Enterprise Project Portfolio Management+1 | 26/7/2018 | 17/6/2026 | In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss. | |
| Modificada | Crítica (9.8) | 2.1% | — | EMC Data Protection Advisor | 16/3/2018 | 17/6/2026 | EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are: "Apollo System Test", "emc.dpa.agent.logon" and "emc.dpa.metrics.logon". An attacker with knowledge of the password could potentially use… | |
| Modificada | Alta (7.8) | 0.34% | — | EMC Data Protection Advisor | 12/3/2018 | 17/6/2026 | Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with administrative privileges. The affected account is "apollosuperuser." An attacker with local access to the server where DPA Datastore Service… | |
| Modificada | Media (5.3) | 0.62% | — | Tripadvisor Tamobileapp | 9/3/2018 | 17/6/2026 | The TripAdvisor app with the versions before TAMobileApp-24.6.4 pre-installed in some Huawei mobile phones have an arbitrary URL loading vulnerability due to insufficient input validation and improper configuration. An attacker may exploit this vulnerability to invoke TripAdvisor to load a specific URL and execute… | |
| Modificada | Alta (8.8) | 6.7% | — | EMC Data Protection Advisor | 19/10/2017 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vulnerability. The specific flaw exists within the EMC DPA Application service, which listens on TCP port 9002 by default. When parsing the… | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa | Apache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+54 | 4/10/2017 | 25/8/2026 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP… | |
| Analizada | Alta (8.1) | 100% | ⚠ Explotación activa | Apache TomcatNetapp 7-mode Transition ToolNetapp Oncommand BalanceNetapp Oncommand Shift+18 | 19/9/2017 | 6/8/2026 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed… | |
| Modificada | Media (4.9) | 2.6% | — | EMC Data Protection Advisor | 9/7/2017 | 17/6/2026 | EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged user may potentially exploit this vulnerability to access unauthorized information from the underlying OS server by supplying specially crafted strings in input parameters of the application. | |
| Modificada | Alta (8.8) | 2.3% | — | EMC Data Protection Advisor | 9/7/2017 | 17/6/2026 | EMC Data Protection Advisor prior to 6.4 contains multiple blind SQL injection vulnerabilities. A remote authenticated attacker may potentially exploit these vulnerabilities to gain information about the application by causing execution of arbitrary SQL commands. | |
| Modificada | Alta (7.5) | 11% | — | NettyRedhat Jboss Data GridRedhat Jboss Middleware Text-only AdvisoriesApache Cassandra | 13/4/2017 | 17/6/2026 | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). |