Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8) | 0.68% | — | HP Version Control Repository Manager | 15/2/2018 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6. | |
| Modificada | Media (6.1) | 1.2% | — | Sonatype Nexus Repository Manager | 9/2/2018 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the… | |
| Modificada | Media (6.1) | 1.1% | — | Sonatype Nexus Repository Manager | 9/2/2018 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File… | |
| Modificada | Crítica (9.8) | 0.71% | — | Sonatype Nexus Repository Manager | 17/12/2017 | 17/6/2026 | Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature. | |
| Analizada | Alta (8.8) | 68% | ⚠ Explotación activa | Adobe AIR SDKAdobe AIR SDK & CompilerAdobe Flash PlayerAdobe AIR+13 | 28/12/2015 | 17/6/2026 | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified… | |
| Modificada | Media (4) | 1.7% | — | HP Version Control Repository Manager | 26/8/2015 | 17/6/2026 | HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to gain privileges and obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6) | 0.87% | — | HP Version Control Repository Manager | 26/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (6.8) | 2.1% | — | HP Version Control Repository Manager | 26/8/2015 | 17/6/2026 | HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.5) | 2.8% | — | HP Version Control Repository Manager | 26/8/2015 | 17/6/2026 | HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to execute arbitrary code or cause a denial of service via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | HP Version Control Repository Manager | 26/8/2015 | 17/6/2026 | Buffer overflow in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Adobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+11 | 23/6/2015 | 17/6/2026 | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015. | |
| Modificada | Media (4.3) | 2.9% | — | HPHP Version Control Repository Manager | 28/10/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.51% | — | HP Version Control Repository Manager | 29/6/2005 | 16/6/2026 | HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen. |