Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.90%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.
ModificadaCrítica (9.8)0.92%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.
ModificadaAlta (8.8)0.91%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.
ModificadaAlta (8.8)0.84%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.
ModificadaCrítica (9.8)1.4%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.
ModificadaCrítica (9.8)62%💥 ExploitRocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the…
ModificadaCrítica (9.8)61%💥 ExploitRocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.
ModificadaCrítica (9.8)1.4%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.
ModificadaMedia (6.1)0.57%—Hcltech Verse10/3/202317/6/2026
HCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerability. By tricking a user into clicking a crafted URL, a remote unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
ModificadaAlta (7.8)0.57%—Nvidia Isaac SIMNvidia Omniverse Audio2faceNvidia Omniverse CodeNvidia Omniverse Create+213/1/202317/6/2026
Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a user opens a USD file that contains embedded…
ModificadaMedia (6.5)0.69%—Jenkins Reverse Proxy Auth15/11/202217/6/2026
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
ModificadaAlta (7.5)0.29%—Hcltech Verse1/11/202217/6/2026
The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digital signature of the app after maliciously modifying the app.
ModificadaCrítica (9.8)0.97%—Megazone Reversewall-mds17/10/202217/6/2026
Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution.
ModificadaMedia (6.5)0.62%💥 PoCHoyoverse Mhyprot214/9/202217/6/2026
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allowing local, unprivileged users to execute arbitrary code with SYSTEM privileges on Microsoft Windows systems. The mhyprot2.sys driver must first be installed by a user…
ModificadaAlta (7.8)1.1%—Circuitverse6/9/202217/6/2026
CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue may lead to Remote Code Execution (RCE). A patch is…
ModificadaCrítica (9.8)1.0%—Generalized Electric Vehicle Reverse Engineering Tool Project Generalized Electric Vehicle Reverse Engineering Tool3/8/202217/6/2026
GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp.
ModificadaMedia (5.9)0.33%—Hcltech Verse12/5/202217/6/2026
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was able to be intercepted. In this specific scenario, the application's network traffic was intercepted using a proxy server set up in 'transparent' mode while a certificate…
ModificadaMedia (6.8)0.28%—Nvidia Omniverse CacheNvidia Omniverse Nucleus29/4/202217/6/2026
NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availability.
ModificadaAlta (7.5)3.5%—Microsoft YET Another Reverse Proxy15/4/202217/6/2026
YARP Denial of Service Vulnerability
ModificadaMedia (5.6)0.50%—XENARM Cortex-r7 FirmwareARM Cortex-r8 FirmwareARM Cortex-a57 Firmware+1813/3/202217/6/2026
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive…
ModificadaMedia (4.7)0.30%—Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareARM Neoverse-e1 FirmwareARM Neoverse-v1 Firmware+1810/3/202217/6/2026
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to…
ModificadaCrítica (9.3)1.7%—Nvidia Omniverse Launcher2/2/202217/6/2026
NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of…
ModificadaMedia (6.1)0.41%—Verse-o-matic Project Verse-o-matic16/8/202117/6/2026
The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored…
ModificadaMedia (6.1)0.41%—Telugu Bible Verse Daily Project Telugu Bible Verse Daily16/8/202117/6/2026
The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses containing JavaScript…
ModificadaAlta (7.5)1.00%—Inverse SogoDebian Linux4/6/202117/6/2026
SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network access to the deployment could impersonate users when SAML is the authentication method. (Only versions after 2.0.5a are affected.)
Orbitaley — Vulnerabilidades