Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.9%—Invigo Automatic Device Management25/3/202117/6/2026
A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.
ModificadaAlta (7.5)2.2%—Invigo Automatic Device Management25/3/202117/6/2026
A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.
ModificadaMedia (6.7)0.46%—Siemens Simatic Automatic ToolSiemens Simatic NET PCSiemens Simatic PCS 7Siemens Simatic PCS NEO+1310/6/202017/6/2026
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All…
ModificadaAlta (7.5)1.6%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+131/1/202026/8/2026
ABRT might allow attackers to obtain sensitive information from crash reports.
ModificadaAlta (7.8)0.39%—Redhat Automatic BUG Reporting Tool14/1/202017/6/2026
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment before invoking abrt-action-install-debuginfo, which allows local users to gain privileges.
ModificadaAlta (7.8)0.56%—Redhat Automatic BUG Reporting Tool14/1/202017/6/2026
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method.
ModificadaAlta (7.1)0.40%—Redhat Automatic BUG Reporting Tool14/1/202017/6/2026
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.
ModificadaMedia (6.5)1.1%—Redhat Automatic BUG Reporting ToolRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+314/1/202017/6/2026
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
ModificadaAlta (7.8)0.41%—Redhat Automatic BUG Reporting Tool14/1/202017/6/2026
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.
ModificadaBaja (3.3)0.31%—Redhat Automatic BUG Reporting Tool1/5/201816/6/2026
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.
ModificadaAlta (7)3.0%—Redhat Automatic BUG Reporting Tool9/2/201826/8/2026
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.
ModificadaAlta (7.8)1.1%—NTT Flets Azukuu PC Automatic Backup Tool29/8/201717/6/2026
Untrusted search path vulnerability in Flets Azukeru for Windows Auto Backup Tool v1.0.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)4.8%—Redhat Automatic BUG Reporting Tool26/6/201717/6/2026
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-release in a chroot, or (5) an unspecified root directory related to…
ModificadaMedia (4.7)0.34%—Redhat Automatic BUG Reporting Tool26/6/201717/6/2026
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
ModificadaMedia (5.5)0.42%—Redhat Automatic BUG Reporting Tool26/6/201717/6/2026
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
ModificadaAlta (7.8)0.41%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes…
ModificadaMedia (5.5)0.42%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes…
ModificadaAlta (7.1)0.41%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes…
ModificadaAlta (7.8)0.41%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes…
ModificadaMedia (5.1)0.40%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Automatic Service Request (ASR) executes…
ModificadaMedia (5.1)0.40%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Automatic Service Request (ASR) executes…
ModificadaAlta (7.8)0.43%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes…
ModificadaCrítica (9.8)2.2%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via SFT to compromise Automatic Service Request (ASR).…
ModificadaAlta (7.5)1.5%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Automatic Service Request (ASR).…
ModificadaMedia (5.5)0.41%—Oracle Automatic Service Request24/4/201717/6/2026
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes…