Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
134 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 0.63% | — | Unistra Impatient | 17/1/2023 | 17/6/2026 | IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to the ontology builder. This may allow attackers to steal Protected Health Information. | |
| Modificada | Alta (7.5) | 0.76% | — | Uniswap Universal Router Firmware | 4/1/2023 | 17/6/2026 | Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds. | |
| Modificada | Media (6.5) | 5.2% | 💥 Exploit | Unisharp Laravel Filemanager | 14/9/2022 | 17/6/2026 | UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0. | |
| Modificada | Alta (8.8) | 0.35% | — | Unisys Data Exchange Management Studio | 13/9/2022 | 17/6/2026 | Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur. | |
| Modificada | Alta (8) | 0.33% | — | Dell Evasa Provider Virtual ApplianceDell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360+4 | 31/8/2022 | 17/6/2026 | Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. | |
| Modificada | Crítica (9.8) | 1.2% | — | Unisoc Chipset | 18/3/2022 | 17/6/2026 | The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data. | |
| Modificada | Crítica (9.8) | 1.2% | — | Unisys Messaging Integration Services | 24/1/2022 | 17/6/2026 | Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated. | |
| Modificada | Alta (7.8) | 0.24% | — | Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+3 | 21/1/2022 | 17/6/2026 | The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance. | |
| Modificada | Alta (8) | 0.36% | — | Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+3 | 21/1/2022 | 17/6/2026 | Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338. | |
| Modificada | Alta (7.5) | 0.97% | — | Unisys Clearpath MCP Tcp/ip Networking Services | 12/1/2022 | 17/6/2026 | Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop. | |
| Modificada | Alta (8.8) | 1.8% | — | Unisharp Laravel-filemanager | 17/12/2021 | 17/6/2026 | This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an… | |
| Modificada | Alta (7.5) | 0.59% | — | Unisys Cargo Mobile | 14/12/2021 | 17/6/2026 | Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the manifest) is False. | |
| Modificada | Media (6.7) | 0.25% | — | Unisys Stealth | 15/7/2021 | 17/6/2026 | Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run. | |
| Modificada | Alta (7.8) | 0.69% | — | Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance+1 | 30/4/2021 | 17/6/2026 | Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions. | |
| Modificada | Media (5.4) | 0.47% | — | Unisys Data Exchange Management Studio | 27/4/2021 | 17/6/2026 | Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack. | |
| Modificada | Media (4.9) | 0.85% | — | Unisys Stealth | 20/4/2021 | 17/6/2026 | Unisys Stealth (core) 5.x before 5.0.048.0, 5.1.x before 5.1.017.0, and 6.x before 6.0.037.0 stores passwords in a recoverable format. | |
| Modificada | Alta (7.8) | 0.23% | — | Unisys Stealth | 18/3/2021 | 17/6/2026 | In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration. | |
| Modificada | Media (5.4) | 0.63% | — | Dell UnisphereDell Powermax OS | 5/1/2021 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject… | |
| Modificada | Alta (7.8) | 0.29% | — | Unisys Stealth | 1/10/2020 | 17/6/2026 | Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials. | |
| Modificada | Alta (8.1) | 0.59% | — | Dell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 23/6/2020 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a… | |
| Modificada | Media (5.4) | 0.75% | — | Dell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell Powermax OS | 23/6/2020 | 17/6/2026 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics. | |
| Modificada | Crítica (9.8) | 0.68% | — | Unisys Stealth | 22/6/2020 | 17/6/2026 | In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key. | |
| Modificada | Alta (8.8) | 0.39% | — | Unisys Algol Compiler | 21/5/2020 | 17/6/2026 | Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences under rare circumstances related to syntax. The resulting code could, for example, trigger a system fault or adversely affect confidentiality, integrity, and availability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Unisoon Ultralog Express Firmware | 27/3/2020 | 17/6/2026 | UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. | |
| Modificada | Alta (7.5) | 0.71% | — | Unisoon Ultralog Express Firmware | 27/3/2020 | 17/6/2026 | UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page. |