Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.7) | 0.48% | — | Numerix License Server Administration SystemAI | 11/12/2024 | 17/6/2026 | Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST… | |
| Modificada | Baja (3.4) | 1.3% | — | Haxx CurlNetapp OntapNetapp Ontap Select Deploy Administration UtilityNetapp H610c Firmware+7 | 11/12/2024 | 17/6/2026 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either… | |
| Aplazada | Alta (7.2) | 0.27% | — | SAP Netweaver AdministratorAI | 10/12/2024 | 17/6/2026 | SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and… | |
| Analizada | Alta (8.1) | 0.36% | — | Dell Openmanage Server Administrator | 9/12/2024 | 17/6/2026 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or… | |
| Analizada | Alta (8.8) | 0.34% | — | Dell Openmanage Server Administrator | 9/12/2024 | 17/6/2026 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges. | |
| Aplazada | Media (5.3) | 0.47% | — | Inisev Enhanced Text WidgetAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in cl272 Enhanced Text Widget enhanced-text-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through <= 1.6.3. | |
| Aplazada | Media (4.3) | 0.50% | — | Inisev Enhanced Text WidgetAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.5.8. | |
| Aplazada | Alta (8.5) | 0.40% | — | QUY LE 91 Administrator ZAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quý Lê 91 Administrator Z administrator-z allows Blind SQL Injection.This issue affects Administrator Z: from n/a through < 2024.10.21. | |
| Analizada | Alta (8.8) | 1.1% | — | Wellchoose Administrative Management System | 21/10/2024 | 17/6/2026 | Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands. | |
| Analizada | Alta (8.8) | 0.60% | — | Wellchoose Administrative Management System | 21/10/2024 | 17/6/2026 | Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells. | |
| Analizada | Alta (7.5) | 0.72% | — | Wellchoose Administrative Management System | 21/10/2024 | 17/6/2026 | Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server. | |
| Analizada | Media (6.5) | 0.20% | — | Lenovo Xclarity Administrator | 13/9/2024 | 17/6/2026 | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call. | |
| Analizada | Media (4.3) | 0.34% | — | Lenovo Xclarity Administrator | 13/9/2024 | 17/6/2026 | A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges. | |
| Analizada | Media (6.5) | 0.73% | — | Haxx CurlDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+6 | 11/9/2024 | 17/6/2026 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for… | |
| Modificada | Alta (7.5) | 67% | — | OpensslNetapp Active IQ Unified ManagerManagement Services FOR Element Software AND Netapp HCINetapp Ontap 9+15 | 3/9/2024 | 17/6/2026 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service.… | |
| Modificada | Alta (7.5) | 0.63% | — | Rust-bitcoin Miniscript | 19/8/2024 | 17/6/2026 | The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properly track tree depth. | |
| Analizada | Media (6.9) | 0.55% | — | Forip Administracao Pabx | 5/8/2024 | 17/6/2026 | A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the component monitcallcenter. The manipulation of the argument user leads to sql injection. The attack may be launched remotely.… | |
| Modificada | Media (5.3) | 0.40% | — | Forip Administracao Pabx | 25/7/2024 | 17/6/2026 | A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown function of the file /detalheIdUra of the component Lista Ura Page. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (6.9) | 0.45% | — | Forip Administracao PabxAI | 25/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection. The attack may be initiated remotely. The… | |
| Modificada | Media (5.4) | 0.31% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Inisev Social Media & Share Icons allows Stored XSS.This issue affects Social Media & Share Icons: from n/a through 2.9.1. | |
| Aplazada | Media (6.3) | 0.28% | — | Opentext Netiq Directory AND Resource AdministratorAI | 16/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10. | |
| Modificada | Alta (7.5) | 1.0% | 💥 PoC | CertifiManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration UtilityNetapp Ontap Tools | 5/7/2024 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Analizada | Media (4.8) | 0.15% | — | Siemens TIA Administrator | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process. | |
| Analizada | Alta (7.8) | 0.17% | — | Dell Openmanage Server Administrator | 11/6/2024 | 17/6/2026 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation… |