Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

11.990 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.22%—Veritas Infoscale Operations Manager20/5/202623/7/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en InfoScale v.9.1.3 Operations Manager (VIOM) permite a un atacante forzar al usuario con una sesión activa a hacer clic en un enlace HTML malicioso, lo que desencadena modificaciones no intencionadas en la aplicación web de VIOM sin el…
AnalizadaMedia (5.4)0.24%—Veritas Infoscale Operations Manager20/5/202623/7/2026
InfoScale VIOM 9.1.3 permite XSS.
AnalizadaMedia (6.5)0.35%—Veritas Infoscale Operations Manager20/5/202623/7/2026
Inyección SQL en InfoScale VIOM anterior a la v9.1.3 permite a atacantes remotos escalar privilegios.
AnalizadaAlta (7.5)0.35%—Dell Powerflex Appliance Intelligent CatalogDell Powerflex ManagerDell Powerflex Rack20/5/20265/10/2026
Dell PowerFlex Manager, versión(es) menor o igual a 4.6.2, contiene una vulnerabilidad de Exposición de Información a Través de Listado de Directorios. Un atacante no autenticado con acceso remoto podría potencialmente explotar esta vulnerabilidad, lo que llevaría a la exposición de información.
AplazadaMedia (6.4)0.33%—Wp-master Logo Manager FOR EnamadAI20/5/202624/7/2026
El plugin Logo Manager For Enamad para WordPress es vulnerable a Stored Cross-Site Scripting a través del atributo title de los shortcodes 'vc_enamad_namad', 'vc_enamad_shamed' y 'vc_enamad_custom' en todas las versiones hasta la 0.7.4, inclusive, debido a una sanitización de entrada y un escape de salida…
AnalizadaCrítica (10)0.90%—Microsoft Azure LocalMicrosoft Azure Resource Manager18/5/202617/6/2026
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (5.1)0.21%—Wplearnmanager WP Learn ManagerAI16/5/202617/6/2026
WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the `fieldtitle` parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle field to execute arbitrary JavaScript…
Pendiente de análisisAlta (8.5)0.11%—OKI Spsv Port ManagerAI16/5/202617/6/2026
OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unquoted path. Attackers can place a malicious executable in a directory within the service path that will execute with…
AplazadaMedia (6.9)0.15%—Internet Download ManagerAI16/5/202629/9/2026
Internet Download Manager 6.38.12 contiene una vulnerabilidad de desbordamiento de búfer en el componente Programador que permite a atacantes locales bloquear la aplicación al proporcionar una entrada de tamaño excesivo. Los atacantes pueden pegar datos maliciosos que excedan los 5000 bytes en el campo 'Abrir el…
AnalizadaAlta (8.6)1.0%💥 PoCCisco Catalyst Sd-wan Manager14/5/202629/6/2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML…
AnalizadaMedia (5.4)0.19%—Cisco Catalyst Sd-wan Manager14/5/202629/6/2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive…
AnalizadaMedia (5.4)0.19%—Cisco Catalyst Sd-wan Manager14/5/202629/6/2026
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information…
AnalizadaCrítica (10)92%⚠ Explotación activa💥 PoCCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller14/5/202617/6/2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain…
AnalizadaAlta (8.3)0.93%—F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+313/5/202618/6/2026
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be…
ModificadaCrítica (9.2)3.4%💥 PoCF5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+313/5/202610/9/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes…
AnalizadaAlta (7.1)0.28%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202617/6/2026
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information. Note: Software versions which have reached End of Technical Support (EoTS) are…
AnalizadaMedia (6.3)0.73%—F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+313/5/202618/6/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers' control to cause a…
En análisisAlta (8.5)0.58%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.3)0.34%💥 PoCF5 Nginx Gateway FabricF5 Nginx Open SourceF5 Nginx Instance ManagerF5 Nginx Ingress Controller13/5/202618/6/2026
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.5)0.41%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.46%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (7.1)0.42%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202618/6/2026
A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (7.1)0.27%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202623/6/2026
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.46%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+1913/5/202623/6/2026
When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.7)0.11%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202623/6/2026
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.