Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

134 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.6)0.63%—Unistra Impatient17/1/202317/6/2026
IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to the ontology builder. This may allow attackers to steal Protected Health Information.
ModificadaAlta (7.5)0.76%—Uniswap Universal Router Firmware4/1/202317/6/2026
Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.
ModificadaMedia (6.5)5.2%💥 ExploitUnisharp Laravel Filemanager14/9/202217/6/2026
UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.
ModificadaAlta (8.8)0.35%—Unisys Data Exchange Management Studio13/9/202217/6/2026
Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur.
ModificadaAlta (8)0.33%—Dell Evasa Provider Virtual ApplianceDell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360+431/8/202217/6/2026
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.
ModificadaCrítica (9.8)1.2%—Unisoc Chipset18/3/202217/6/2026
The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.
ModificadaCrítica (9.8)1.2%—Unisys Messaging Integration Services24/1/202217/6/2026
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.
ModificadaAlta (7.8)0.24%—Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+321/1/202217/6/2026
The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.
ModificadaAlta (8)0.36%—Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere 360Dell Unisphere FOR Powermax+321/1/202217/6/2026
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.
ModificadaAlta (7.5)0.97%—Unisys Clearpath MCP Tcp/ip Networking Services12/1/202217/6/2026
Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.
ModificadaAlta (8.8)1.8%—Unisharp Laravel-filemanager17/12/202117/6/2026
This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an…
ModificadaAlta (7.5)0.59%—Unisys Cargo Mobile14/12/202117/6/2026
Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the manifest) is False.
ModificadaMedia (6.7)0.25%—Unisys Stealth15/7/202117/6/2026
Unisys Stealth 5.1 before 5.1.025.0 and 6.0 before 6.0.055.0 has an unquoted Windows search path for a scheduled task. An unintended executable might run.
ModificadaAlta (7.8)0.69%—Dell Solutions EnablerDell Solutions Enabler Virtual ApplianceDell Unisphere FOR PowermaxDell Unisphere FOR Powermax Virtual Appliance+130/4/202117/6/2026
Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.
ModificadaMedia (5.4)0.47%—Unisys Data Exchange Management Studio27/4/202117/6/2026
Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack.
ModificadaMedia (4.9)0.85%—Unisys Stealth20/4/202117/6/2026
Unisys Stealth (core) 5.x before 5.0.048.0, 5.1.x before 5.1.017.0, and 6.x before 6.0.037.0 stores passwords in a recoverable format.
ModificadaAlta (7.8)0.23%—Unisys Stealth18/3/202117/6/2026
In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration.
ModificadaMedia (5.4)0.63%—Dell UnisphereDell Powermax OS5/1/202117/6/2026
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject…
ModificadaAlta (7.8)0.29%—Unisys Stealth1/10/202017/6/2026
Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials.
ModificadaAlta (8.1)0.59%—Dell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell Powermax OS23/6/202017/6/2026
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a…
ModificadaMedia (5.4)0.75%—Dell EMC Unisphere FOR PowermaxDell EMC Unisphere FOR Powermax Virtual ApplianceDell Powermax OS23/6/202017/6/2026
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics.
ModificadaCrítica (9.8)0.68%—Unisys Stealth22/6/202017/6/2026
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key.
ModificadaAlta (8.8)0.39%—Unisys Algol Compiler21/5/202017/6/2026
Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences under rare circumstances related to syntax. The resulting code could, for example, trigger a system fault or adversely affect confidentiality, integrity, and availability.
ModificadaCrítica (9.8)1.2%—Unisoon Ultralog Express Firmware27/3/202017/6/2026
UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
ModificadaAlta (7.5)0.71%—Unisoon Ultralog Express Firmware27/3/202017/6/2026
UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.
Orbitaley — Vulnerabilidades