Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

354 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.6%—Vmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
ModificadaCrítica (9.8)70%💥 ExploitVmware Aria Operations FOR LogsVmware Cloud Foundation20/4/202317/6/2026
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
ModificadaAlta (8.8)0.35%—ABB Symphony Plus S+ Operations2/3/202317/6/2026
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
ModificadaAlta (8.8)0.40%—Vmware Vrealize Operations1/2/202317/6/2026
VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.
ModificadaMedia (4.9)0.82%—Vmware Vrealize Operations16/12/202217/6/2026
vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.
ModificadaAlta (7.2)0.99%—Vmware Vrealize Operations16/12/202217/6/2026
vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
ModificadaMedia (5.4)0.65%—Microfocus Operations BridgeMicrofocus Operations Bridge Manager8/12/202217/6/2026
A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The vulnerability is only applicable if the…
ModificadaMedia (4.9)0.64%—Vmware Vrealize Operations11/10/202217/6/2026
VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data.
ModificadaAlta (7.5)0.83%—Vmware Vrealize Operations10/8/202217/6/2026
VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.
ModificadaMedia (4.3)0.64%—Vmware Vrealize Operations10/8/202217/6/2026
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
ModificadaAlta (8.8)1.8%—Vmware Vrealize Operations10/8/202217/6/2026
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution.
ModificadaAlta (7.2)0.65%—Vmware Vrealize Operations10/8/202217/6/2026
VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.
ModificadaAlta (7.8)0.60%—Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager9/8/202217/6/2026
System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
ModificadaAlta (8.2)1.1%—Jenkins Compuware Ispw Operations27/7/202217/6/2026
Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
ModificadaMedia (4.3)0.68%—Jenkins Compuware Ispw Operations27/7/202217/6/2026
A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.
ModificadaMedia (5.3)1.6%—IBM Spectrum Protect Operations Center30/6/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.
ModificadaCrítica (9.8)1.1%—IBM Spectrum Protect Operations Center17/6/202217/6/2026
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain…
ModificadaAlta (7.8)0.92%—Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+615/6/202217/6/2026
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
ModificadaMedia (5.5)1.5%—RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+127/4/202217/6/2026
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional…
ModificadaAlta (7.8)2.3%—RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+127/4/202217/6/2026
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution…
ModificadaCrítica (9.8)2.0%—Microfocus Operations Bridge11/4/202217/6/2026
Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be exploited to unauthenticated remote code…
ModificadaBaja (2.4)0.20%—IBM Spectrum Protect Operations Center14/3/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could allow a page linked to from within Operations Center to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL…
ModificadaAlta (8.8)0.38%—IBM Spectrum Protect Operations Center14/3/202217/6/2026
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220048.
ModificadaMedia (4.9)2.7%—Veritas Infoscale Operations Manager4/3/202217/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By…
ModificadaMedia (4.8)0.45%—Veritas Infoscale Operations Manager4/3/202217/6/2026
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter…
Orbitaley — Vulnerabilidades