Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.0%—Solarwinds Network Configuration Manager9/11/202317/6/2026
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226
ModificadaMedia (4.9)0.44%—Solarwinds Network Configuration Manager1/11/202317/6/2026
The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitive information.
ModificadaAlta (8.8)1.8%—Solarwinds Network Configuration Manager1/11/202317/6/2026
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges.
ModificadaAlta (8.8)1.8%—Solarwinds Network Configuration Manager1/11/202317/6/2026
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges.
ModificadaCrítica (9.8)0.62%—NI System Configuration18/10/202317/6/2026
A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execution. Successful exploitation requires that an attacker can provide a specially crafted response. This affects NI System Configuration 2023 Q3 and all previous versions.
ModificadaMedia (4.4)0.18%—F5 Big-ip Access Policy ManagerF5 Big-ip Guided Configuration10/10/202317/6/2026
When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (7.5)0.72%—Doverfuelingsolutions Maglink LX WEB Console Configuration11/9/202317/6/2026
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 vulnerable to a path traversal attack, which could allow an attacker to access files stored on the system.
ModificadaAlta (8.8)0.65%—Doverfuelingsolutions Maglink LX WEB Console Configuration11/9/202317/6/2026
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges.
ModificadaCrítica (9.1)0.93%—Doverfuelingsolutions Maglink LX WEB Console Configuration11/9/202317/6/2026
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access.
ModificadaAlta (8.8)0.91%—Jenkins JOB Configuration History6/9/202317/6/2026
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (6.5)0.67%—Jenkins JOB Configuration History6/9/202317/6/2026
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.
ModificadaMedia (5.4)0.50%—Jenkins JOB Configuration History6/9/202317/6/2026
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not property sanitize or escape the timestamp value from history entries when rendering a history entry on the history view, resulting in a stored cross-site scripting (XSS) vulnerability.
ModificadaMedia (4.3)0.92%—Jenkins JOB Configuration History6/9/202317/6/2026
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.
ModificadaAlta (8.8)1.1%—Zohocorp Manageengine Network Configuration Manager4/8/202317/6/2026
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
ModificadaAlta (7.2)3.2%—Solarwinds Network Configuration Monitor26/7/202317/6/2026
The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
ModificadaAlta (7.8)0.15%—Intel Setup AND Configuration Software10/5/202317/6/2026
Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.16%—Intel Setup AND Configuration Software10/5/202317/6/2026
Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.16%—Intel Endpoint Management Assistant Configuration ToolIntel Manageability Commander10/5/202317/6/2026
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.5)0.76%—Angular-server-side-configuration Project Angular-server-side-configuration24/3/202317/6/2026
angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) files during build time of an Angular CLI project. The detected environment…
ModificadaMedia (6.1)0.37%—Johnsoncontrols Metasys System Configuration Tool9/2/202317/6/2026
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
ModificadaMedia (6.1)0.55%—Johnsoncontrols Metasys System Configuration Tool9/2/202317/6/2026
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
ModificadaAlta (7.5)0.70%—Oracle Siebel Core - DB Deployment AND Configuration Accessible Data18/10/202217/6/2026
Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Repository Utilities). Supported versions that are affected are 22.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB…
ModificadaMedia (6.5)0.55%—Solarwinds Network Configuration Manager10/10/202217/6/2026
An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.
ModificadaMedia (5.3)0.58%—Teclib-edition System Center Configuration Manager22/9/202217/6/2026
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.
ModificadaCrítica (9.8)0.93%—Jenkins Compuware Common Configuration21/9/202217/6/2026
Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.