Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.27% | — | Dell Common Event Enabler | 8/4/2025 | 17/6/2026 | Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource with an Insecure Default vulnerability in the Common Anti-Virus Agent (CAVA). An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (8.8) | 0.92% | — | Apache Airflow Common SQL Provider | 7/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI User could inject arbitrary SQL command when triggering DAG… | |
| Aplazada | Media (5.9) | 0.21% | — | Commoninja Paytm Payment DonationAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in integrationdevpaytm Paytm Payment Donation paytm-donation allows Stored XSS.This issue affects Paytm Payment Donation: from n/a through <= 2.3.3. | |
| Analizada | Media (5) | 0.87% | — | Apache Commons VFS | 23/3/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects… | |
| Modificada | Alta (7.5) | 1.4% | — | Apache Commons VFS | 23/3/2025 | 17/6/2026 | Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the… | |
| Analizada | Media (6.5) | 0.38% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an authenticated user to cause a denial of service in the Hardware Security Module (HSM) using a specially crafted sequence of valid requests. | |
| Analizada | Baja (3.7) | 0.26% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations. | |
| Analizada | Media (6.5) | 0.44% | — | IBM Common Cryptographic Architecture | 11/3/2025 | 17/6/2026 | IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the creation of ECDSA signatures to perform a timing-based attack. | |
| Analizada | Media (5.9) | 0.63% | — | Abseil Common LibrariesDebian Linux | 21/2/2025 | 17/6/2026 | There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to pass a very large size that would cause an integer overflow when… | |
| Aplazada | Alta (7.1) | 0.26% | — | Commoninja Paytm Payment DonationAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in integrationdevpaytm Paytm Payment Donation paytm-donation allows Reflected XSS.This issue affects Paytm Payment Donation: from n/a through <= 2.3.1. | |
| Analizada | Media (6.5) | 0.27% | — | IBM Common Licensing | 26/1/2025 | 17/6/2026 | IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism. | |
| Analizada | Media (5.5) | 0.14% | — | IBM Common Licensing | 26/1/2025 | 17/6/2026 | IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user. | |
| Analizada | Media (4.3) | 0.31% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 21/1/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC… | |
| Analizada | Media (4.3) | 0.33% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 21/1/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC… | |
| Aplazada | Media (6.5) | 0.37% | — | Commonninja Compare NinjaAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Common Ninja Compare Ninja compare-ninja-comparison-tables allows Stored XSS.This issue affects Compare Ninja: from n/a through <= 2.1.0. | |
| Analizada | Media (5.4) | 0.29% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Analizada | Media (5.4) | 0.29% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Analizada | Media (5.4) | 0.37% | — | Cisco Crosswork Network ControllerCisco Common Services Platform Collector | 8/1/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the… | |
| Aplazada | Media (6.4) | 0.31% | — | Commonninja Common NinjaAI | 7/1/2025 | 17/6/2026 | The Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'commonninja' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user… | |
| Aplazada | Alta (7.1) | 0.30% | — | Hitachi OPS Center Common ServicesAIHitachi OPS Center OVAAI | 3/12/2024 | 17/6/2026 | Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01. | |
| Aplazada | Alta (8.8) | 0.98% | — | Simplesamlphp Xml-commonAI | 2/12/2024 | 17/6/2026 | SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0. | |
| Aplazada | Media (6.5) | 0.38% | — | Commonninja Pricer Ninja Pricing TablesAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Common Ninja Pricer Ninja pricer-ninja-pricing-tables allows Stored XSS.This issue affects Pricer Ninja: from n/a through <= 2.1.0. | |
| Analizada | Alta (8.7) | 0.48% | — | Talyssonoc Commonregexjs | 26/10/2024 | 17/6/2026 | CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available. | |
| Analizada | Media (5.4) | 0.33% | — | Oracle Peoplesoft Enterprise Cost Center Common Application Objects | 15/10/2024 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC… | |
| Analizada | Media (4.3) | 1.3% | — | Apache Commons IONetapp Active IQ Unified ManagerNetapp BluexpNetapp E-series Santricity Unified Manager+4 | 3/10/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0… |