Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.93% | — | Oracle Financials Common Modules | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Advanced Global Intercompany). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common… | |
| Modificada | Alta (7.5) | 1.5% | — | Varnish-cache Varnish-modulesVarnish-cache Varnish-modules KlarlackFedoraproject Fedora | 16/3/2021 | 17/6/2026 | Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure… | |
| Modificada | Alta (7.8) | 0.34% | — | Soundresearch Dchu Model Software Component Modules | 13/1/2021 | 17/6/2026 | The SECOMN service in Sound Research DCHU model software component modules (APO) through 2.0.9.17, delivered on HP Windows 10 computers, may allow escalation of privilege via a fake DLL. (As a resolution, Windows Update is being submitted for all affected products to update to 2.0.9.18 or later.) | |
| Modificada | Media (6.4) | 0.21% | — | AMD Trusted Platform Modules Reference | 12/11/2020 | 17/6/2026 | The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be compromised. AMD believes that the attack requires physical access of the device because the power… | |
| Modificada | Media (6.5) | 0.61% | — | Jenkins Self-organizing Swarm Modules | 3/6/2020 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove agent labels. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Self-organizing Swarm Modules | 3/6/2020 | 17/6/2026 | Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels. | |
| Modificada | Media (6.7) | 0.61% | — | Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+23 | 13/5/2019 | 17/6/2026 | A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based… | |
| Modificada | Crítica (9.3) | 1.8% | — | Jenkins Self-organizing Swarm Modules | 30/4/2019 | 17/6/2026 | Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients. | |
| Modificada | Media (6.5) | 4.8% | — | Fasterxml Jackson-modules-java8Oracle ClusterwareOracle Database ServerOracle Global Lifecycle Management Opatch+2 | 20/12/2018 | 17/6/2026 | Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a… | |
| Modificada | Alta (8.1) | 4.2% | — | Siemens Simatic CP 44x-1 Redundant Network Access Modules | 7/7/2017 | 17/6/2026 | An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may be able to perform administrative actions on the Communication Process (CP) of the RNA series module, if network access to Port 102/TCP is available and the configuration… | |
| Modificada | Baja (3.3) | 0.37% | — | Node Packaged Modules Project Node Packaged Modules | 22/4/2014 | 16/6/2026 | lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives. | |
| Modificada | Media (6.9) | 0.38% | — | Canonical Libpam-modulesCanonical Ubuntu Linux | 15/4/2014 | 16/6/2026 | Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using… | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Webbiscuits Modules Controller | 14/2/2009 | 16/6/2026 | Directory traversal vulnerability in faqsupport/wce.download.php in WebBiscuits Modules Controller 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Webbiscuits Modules Controller | 14/2/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. | |
| Modificada | Alta (9) | 2.6% | — | Cisco Catalyst 3750 Series Integrated Wireless LAN ControllerCisco Catalyst 6500 Wireless Services ModulesCisco Wireless LAN Controller Software | 5/2/2009 | 16/6/2026 | Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges via unknown vectors, as demonstrated by escalation from the… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Content Switching Module With SSLCisco Content Switching Modules | 10/9/2007 | 16/6/2026 | Cisco Content Switching Modules (CSM) 4.2 before 4.2.3a, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.2a, allow remote attackers to cause a denial of service (CPU consumption or reboot) via sets of out-of-order TCP packets with unspecified characteristics, aka CSCsd27478. | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Content Switching Module With SSLCisco Content Switching Modules | 10/9/2007 | 16/6/2026 | Cisco Content Switching Modules (CSM) 4.2 before 4.2.7, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.6, when service termination is enabled, allow remote attackers to cause a denial of service (reboot) via unspecified vectors related to high network utilization, aka CSCsh57876. | |
| Modificada | Crítica (9.8) | 2.4% | — | Comdev Modules Builder | 2/5/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability because the unmodified scripts set the… |