Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.6% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root. | |
| Modificada | Alta (8.8) | 0.35% | — | ABB Symphony Plus S+ Operations | 2/3/2023 | 17/6/2026 | Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2. | |
| Modificada | Alta (8.8) | 0.40% | — | Vmware Vrealize Operations | 1/2/2023 | 17/6/2026 | VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user. | |
| Modificada | Media (4.9) | 0.82% | — | Vmware Vrealize Operations | 16/12/2022 | 17/6/2026 | vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4. | |
| Modificada | Alta (7.2) | 0.99% | — | Vmware Vrealize Operations | 16/12/2022 | 17/6/2026 | vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | |
| Modificada | Media (5.4) | 0.65% | — | Microfocus Operations BridgeMicrofocus Operations Bridge Manager | 8/12/2022 | 17/6/2026 | A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the… | |
| Modificada | Media (4.9) | 0.64% | — | Vmware Vrealize Operations | 11/10/2022 | 17/6/2026 | VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data. | |
| Modificada | Alta (7.5) | 0.83% | — | Vmware Vrealize Operations | 10/8/2022 | 17/6/2026 | VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges. | |
| Modificada | Media (4.3) | 0.64% | — | Vmware Vrealize Operations | 10/8/2022 | 17/6/2026 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure. | |
| Modificada | Alta (8.8) | 1.8% | — | Vmware Vrealize Operations | 10/8/2022 | 17/6/2026 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution. | |
| Modificada | Alta (7.2) | 0.65% | — | Vmware Vrealize Operations | 10/8/2022 | 17/6/2026 | VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root. | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager | 9/8/2022 | 17/6/2026 | System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.2) | 1.1% | — | Jenkins Compuware Ispw Operations | 27/7/2022 | 17/6/2026 | Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties. | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Compuware Ispw Operations | 27/7/2022 | 17/6/2026 | A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (5.3) | 1.6% | — | IBM Spectrum Protect Operations Center | 30/6/2022 | 17/6/2026 | IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940. | |
| Modificada | Crítica (9.8) | 1.1% | — | IBM Spectrum Protect Operations Center | 17/6/2022 | 17/6/2026 | In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain… | |
| Modificada | Alta (7.8) | 0.92% | — | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+6 | 15/6/2022 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Media (5.5) | 1.5% | — | RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+1 | 27/4/2022 | 17/6/2026 | Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional… | |
| Modificada | Alta (7.8) | 2.3% | — | RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+1 | 27/4/2022 | 17/6/2026 | Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution… | |
| Modificada | Crítica (9.8) | 2.0% | — | Microfocus Operations Bridge | 11/4/2022 | 17/6/2026 | Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be exploited to unauthenticated remote code… | |
| Modificada | Baja (2.4) | 0.20% | — | IBM Spectrum Protect Operations Center | 14/3/2022 | 17/6/2026 | IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could allow a page linked to from within Operations Center to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL… | |
| Modificada | Alta (8.8) | 0.38% | — | IBM Spectrum Protect Operations Center | 14/3/2022 | 17/6/2026 | IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220048. | |
| Modificada | Media (4.9) | 2.7% | — | Veritas Infoscale Operations Manager | 4/3/2022 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By… | |
| Modificada | Media (4.8) | 0.45% | — | Veritas Infoscale Operations Manager | 4/3/2022 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter… |