Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1353 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.5% | — | HP Network Node Manager I | 10/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0, 9.10, and 9.20 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.3) | 0.37% | — | Node Packaged Modules Project Node Packaged Modules | 22/4/2014 | 16/6/2026 | lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives. | |
| Modificada | Alta (10) | 8.7% | — | HP Network Node Manager I | 19/4/2014 | 17/6/2026 | Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 5.7% | 💥 PoC | Google ChromeGoogle V8Nodejs Node.jsDebian Linux | 5/3/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | |
| Modificada | Media (4.3) | 0.95% | — | IBM Integrated Management Module 2IBM BladecenterIBM Flex System Manager Node 7955IBM Flex System Manager Node 8731+27 | 21/1/2014 | 16/6/2026 | Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic. | |
| Modificada | Media (6.8) | 4.8% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary AUS+6 | 15/1/2014 | 16/6/2026 | Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX. | |
| Modificada | Media (5.1) | 6.3% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary AUS+6 | 15/1/2014 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, and CVE-2014-0424. | |
| Modificada | Media (4.3) | 4.9% | — | Oracle JREHP JDKHP JRERedhat Enterprise Linux Desktop Supplementary+6 | 15/1/2014 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect availability via unknown vectors related to JavaFX. | |
| Modificada | Media (5.1) | 6.3% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary AUS+6 | 15/1/2014 | 16/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install, a different vulnerability than CVE-2013-5905. | |
| Modificada | Media (6.8) | 4.9% | — | Oracle JRERedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server Supplementary+5 | 15/1/2014 | 16/6/2026 | Unspecified vulnerability in Oracle Java SE 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. | |
| Modificada | Media (5) | 5.7% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary AUS+6 | 15/1/2014 | 16/6/2026 | Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality via unknown vectors related to JavaFX. | |
| Modificada | Alta (7.5) | 3.5% | — | Webbynode | 19/12/2013 | 17/6/2026 | The message function in lib/webbynode/notify.rb in the Webbynode gem 1.0.5.3 and earlier for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a growlnotify message. | |
| Modificada | Media (5) | 37% | — | Nodejs | 21/10/2013 | 16/6/2026 | The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response. | |
| Modificada | Media (5) | 1.4% | — | Adcisolutions Node View Permissions | 30/9/2013 | 16/6/2026 | The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by reading a node listing. | |
| Modificada | Media (5.8) | 1.3% | — | Node Access User Reference Project Nodeaccess Userreference Module | 28/8/2013 | 16/6/2026 | The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the… | |
| Modificada | Media (4) | 0.78% | — | IBM BladecenterIBM Flex System X220 Compute NodeIBM Flex System X240 Compute NodeIBM Flex System X440 Compute Node+26 | 9/8/2013 | 16/6/2026 | The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information by reading a file. | |
| Modificada | Media (4.3) | 0.95% | — | IBM BladecenterIBM Flex System X220 Compute NodeIBM Flex System X240 Compute NodeIBM Flex System X440 Compute Node+26 | 9/8/2013 | 16/6/2026 | The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for… | |
| Modificada | Alta (10) | 2.0% | — | IBM BladecenterIBM Flex System X220 Compute NodeIBM Flex System X240 Compute NodeIBM Flex System X440 Compute Node+26 | 9/8/2013 | 16/6/2026 | The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers… | |
| Modificada | Alta (7.5) | 3.2% | — | Google ChromeRedhat OpenstackDebian LinuxNodejs Node.js | 31/7/2013 | 16/6/2026 | Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion." | |
| Modificada | Media (5) | 2.7% | — | Redhat Jboss Communications PlatformRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal Platform+3 | 29/7/2013 | 16/6/2026 | wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communications Platform 1.2.11 and 5.1.1; JBoss Enterprise BRMS Platform 5.1.0;… | |
| Modificada | Alta (7.5) | 3.7% | — | HP Network Node Manager I | 13/7/2013 | 16/6/2026 | Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.00, 9.1x, and 9.2x allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (6.8) | 17% | 💥 Exploit | Nodeca Js-yaml | 28/6/2013 | 16/6/2026 | The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation. | |
| Modificada | Media (4.3) | 0.95% | — | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux HPC Node+5 | 21/5/2013 | 16/6/2026 | rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials. | |
| Modificada | Media (5) | 1.2% | — | Cisco Webex Meetings ServerCisco Webex Node FOR ASR 1000 SeriesCisco Webex Node FOR MCS | 4/5/2013 | 16/6/2026 | The HTTP implementation in Cisco WebEx Node for MCS, WebEx Meetings Server, and WebEx Node for ASR 1000 Series allows remote attackers to read the contents of uninitialized memory locations via a crafted request, aka Bug IDs CSCue36672, CSCue31363, CSCuf17466, and CSCug61252. | |
| Modificada | Media (5) | 1.2% | — | Cisco Webex Meetings ServerCisco Webex Node FOR MCS | 3/5/2013 | 16/6/2026 | The HTTP implementation in Cisco WebEx Node for MCS and WebEx Meetings Server allows remote attackers to read cache files via a crafted request, aka Bug IDs CSCue36664 and CSCue36629. |