Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.4% | — | Tibco Activematrix BusinessworksActivematrix Businessworks Distribution FOR Tibco Silver Fabric | 8/8/2018 | 17/6/2026 | The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages,… | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Distribution FOR Python | 1/8/2018 | 17/6/2026 | Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypass URI sanitization via local vector. | |
| Analizada | Alta (8.1) | 99% | ⚠ Explotación activa💥 Exploit | Apache StrutsCisco Digital Media ManagerCisco Hosted Collaboration SolutionCisco Media Experience Engine+3 | 15/9/2017 | 17/6/2026 | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads. | |
| Modificada | Alta (7.5) | 8.3% | — | Apache TomcatDebian LinuxNetapp Oncommand InsightNetapp Oncommand Shift+11 | 11/8/2017 | 17/6/2026 | A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet. | |
| Modificada | Alta (7.5) | 8.1% | — | Apache TomcatOracle Tekelec Platform DistributionDebian LinuxNetapp Oncommand Insight+10 | 10/8/2017 | 17/6/2026 | The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web… | |
| Modificada | Media (5.3) | 7.2% | — | Apache TomcatDebian LinuxRedhat Jboss Enterprise WEB ServerRedhat Enterprise Linux Desktop+10 | 10/8/2017 | 17/6/2026 | When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be… | |
| Modificada | Crítica (9.1) | 10% | — | Apache TomcatNetapp Oncommand InsightNetapp Oncommand ShiftNetapp Snap Creator Framework+11 | 10/8/2017 | 17/6/2026 | In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications. | |
| Modificada | Media (5.9) | 8.0% | — | Apache TomcatCanonical Ubuntu LinuxDebian LinuxRedhat Jboss Enterprise WEB Server+11 | 10/8/2017 | 17/6/2026 | The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default… | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Videoscape Distribution Suite FOR Television | 7/8/2017 | 17/6/2026 | A vulnerability in the cache server within Cisco Videoscape Distribution Suite (VDS) for Television 3.2(5)ES1 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on a targeted appliance. The vulnerability is due to excessive mapped connections exhausting the allotted resources… | |
| Modificada | Media (6.1) | 0.85% | — | Cisco Videoscape Distribution Suite Service Manager | 5/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552. | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Videoscape Distribution Suite FOR Internet Streaming | 1/3/2016 | 17/6/2026 | The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), and 4.1(0) does not properly initiate new TCP sessions when a previous session is in a FIN wait state, which allows remote attackers to cause a denial of service (TCP outage) via vectors involving FIN… | |
| Modificada | Media (6.5) | 0.95% | — | Cisco Videoscape Distribution Suite Service Manager | 12/12/2015 | 17/6/2026 | Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025. | |
| Modificada | Media (5) | 1.8% | — | Cisco Videoscape Distribution Suite Service Manager | 14/11/2015 | 17/6/2026 | Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive information via crafted URLs in REST API requests, aka Bug ID CSCuv86960. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Videoscape Distribution Suite Service BrokerCisco Videoscape Distribution Suite FOR Internet Streaming | 16/7/2015 | 17/6/2026 | Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Internet Streaming (aka VDS-IS or CDS-IS) before 3.3.1 R7 and 4.x before 4.0.0 R4 allow remote attackers to cause a denial of service (device reload) via a crafted HTTP… | |
| Modificada | Alta (9) | 4.2% | — | Cisco Wide Area Application ServicesCisco Application AND Content Networking System SoftwareCisco Enterprise Content Delivery Network SoftwareCisco Internet Streamer Content Delivery System+4 | 1/8/2013 | 16/6/2026 | The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before… | |
| Modificada | Media (5) | 1.2% | — | Tibco Activematrix BPMTibco Activematrix Businessworks Service EngineTibco Activematrix Service BUSTibco Activematrix Service Grid+1 | 13/3/2012 | 16/6/2026 | The server in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to discover credentials via unspecified vectors. | |
| Modificada | Media (4.3) | 0.92% | — | Tibco Silver Fabric Activematrix Service Grid DistributionTibco Activematrix Service GridTibco Activematrix Service BUSTibco Activematrix Businessworks Service Engine+1 | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to inject arbitrary web script or… | |
| Modificada | Media (5) | 1.4% | — | Tibco Activematrix Service BUSTibco Activematrix Service GridTibco Activematrix Businessworks Service EngineTibco Silver Fabric Activematrix Service Grid Distribution+3 | 13/3/2012 | 16/6/2026 | TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before… | |
| Modificada | Alta (7.5) | 1.8% | — | IBM Tivoli Provisioning Manager Express FOR Software Distribution | 6/3/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterAgentKey function in the SoapServlet servlet, (2) the User.updateUserValue function in the… | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | IBM Tivoli Provisioning Manager Express FOR Software Distribution | 6/3/2012 | 16/6/2026 | Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file. | |
| Modificada | Alta (7.5) | 1.1% | — | Infor EclientInfor Enspire Distribution Management Solution | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.34% | — | Openfabrics Enterprise Distribution | 19/9/2011 | 16/6/2026 | ulp/sdp/sdp_proc.c in the ib_sdp module (aka ib_sdp.ko) in the ofa_kernel package in the InfiniBand driver implementation in OpenFabrics Enterprise Distribution (OFED) before 1.5.3 does not properly handle certain non-array variables, which allows local users to cause a denial of service (stack memory corruption and… | |
| Modificada | Alta (7.5) | 5.3% | — | Arcserve Replication AND High AvailabilityCA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication | 7/1/2011 | 16/6/2026 | Buffer overflow in mng_core_com.dll in CA XOsoft Replication r12.0 SP1 and r12.5 SP2 rollup, CA XOsoft High Availability r12.0 SP1 and r12.5 SP2 rollup, CA XOsoft Content Distribution r12.0 SP1 and r12.5 SP2 rollup, and CA ARCserve Replication and High Availability (RHA) r15.0 SP1 allows remote attackers to execute… | |
| Modificada | Media (6.3) | 0.31% | — | Openfabrics Enterprise Distribution | 26/10/2010 | 16/6/2026 | openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_node_desc.sh temporary file. | |
| Modificada | Alta (10) | 17% | — | CA Xosoft Content DistributionCA Xosoft High AvailabilityXosoft Replication | 7/4/2010 | 16/6/2026 | Multiple buffer overflows in CA XOsoft r12.0 and r12.5 allow remote attackers to execute arbitrary code via (1) a malformed request to the ws_man/xosoapapi.asmx SOAP endpoint or (2) a long string to the entry_point.aspx service. |