Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
198 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.7) | 0.73% | — | Tenable.sc | 26/1/2023 | 17/6/2026 | A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could leverage the reporting system to export reports containing formulas, which would then require a victim to approve and execute on a host. | |
| Modificada | Media (6.5) | 0.69% | — | Tenable.sc | 26/1/2023 | 17/6/2026 | A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP injection. | |
| Modificada | Alta (8.8) | 0.82% | — | Tenable Nessus | 20/1/2023 | 17/6/2026 | A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker could potentially execute a specially crafted file to obtain root or NT AUTHORITY / SYSTEM privileges on the Nessus host. | |
| Modificada | Media (6.5) | 0.86% | — | Tenable Nessus | 31/10/2022 | 17/6/2026 | An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of agent logs and data is present. | |
| Modificada | Media (6.5) | 0.86% | — | Tenable Nessus | 25/10/2022 | 17/6/2026 | An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the disclosure of information on the scan target and/or the Nessus scan to unauthorized parties able to reach the Nessus instance. | |
| Modificada | Media (6.5) | 0.70% | — | Tenable Nessus | 17/10/2022 | 17/6/2026 | Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all versions of Nessus Essentials and Professional. The vulnerability allows an attacker to access… | |
| Modificada | Media (6.5) | 0.74% | — | Tenable Nessus | 21/6/2022 | 17/6/2026 | An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials. | |
| Modificada | Alta (8.8) | 1.4% | — | Tenable Nessus | 21/6/2022 | 17/6/2026 | An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges. | |
| Modificada | Alta (8.8) | 1.9% | — | Getcomposer ComposerTenable.scFedoraproject Fedora | 13/4/2022 | 17/6/2026 | Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on packagist.org for example where the… | |
| Modificada | Alta (7.5) | 14% | 💥 PoC | Momentjs MomentTenable.scNetapp Active IQFedoraproject Fedora+1 | 4/4/2022 | 17/6/2026 | Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in… | |
| Modificada | Alta (7.5) | 73% | 💥 PoC | OpensslDebian LinuxNetapp Cloud Volumes Ontap MediatorNetapp Clustered Data Ontap+9 | 15/3/2022 | 17/6/2026 | The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded… | |
| Modificada | Alta (7.5) | 4.0% | 💥 PoC | Libexpat Project LibexpatTenable NessusOracle Communications Metasolv SolutionDebian Linux+2 | 26/1/2022 | 17/6/2026 | Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. | |
| Modificada | Crítica (9.8) | 4.6% | 💥 PoC | Libexpat Project LibexpatNetapp Clustered Data OntapNetapp Oncommand Workflow AutomationTenable Nessus+3 | 24/1/2022 | 17/6/2026 | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. | |
| Modificada | Alta (8.1) | 1.6% | — | Tenable.sc | 14/1/2022 | 17/6/2026 | Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server root of the Tenable.sc host prior to… | |
| Modificada | Alta (8.8) | 2.8% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Alta (8.8) | 2.8% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Alta (8.8) | 2.6% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Crítica (9.8) | 3.4% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Crítica (9.8) | 3.4% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Crítica (9.8) | 4.8% | 💥 PoC | Libexpat Project LibexpatTenable NessusSiemens Sinema Remote Connect ServerDebian Linux | 10/1/2022 | 17/6/2026 | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Alta (7.8) | 3.8% | 💥 PoC | Libexpat Project LibexpatNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Baseboard Management Controller+4 | 6/1/2022 | 17/6/2026 | In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. | |
| Modificada | Alta (8.8) | 4.2% | 💥 PoC | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server+4 | 1/1/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). | |
| Analizada | Crítica (9.8) | 97% | 💥 Exploit | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+10 | 20/12/2021 | 17/6/2026 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. | |
| Modificada | Alta (8.2) | 82% | — | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+8 | 20/12/2021 | 17/6/2026 | A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue… | |
| Modificada | Media (5.3) | 26% | 💥 PoC | PHPNetapp Clustered Data OntapDebian LinuxTenable.sc | 29/11/2021 | 17/6/2026 | In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus… |