Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Microsoft Endpoint Configuration Manager | 20/9/2022 | 17/6/2026 | Microsoft Endpoint Configuration Manager Spoofing Vulnerability | |
| Modificada | Alta (7.8) | 0.21% | — | NI Configuration Manager | 16/9/2022 | 17/6/2026 | An improper input validation in NI System Configuration Manager before 22.5 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.69% | — | Microsoft Azure ARCMicrosoft Azure Guest Configuration | 13/9/2022 | 17/6/2026 | Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 78% | — | Zohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSP+2 | 29/8/2022 | 17/6/2026 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature. | |
| Modificada | Media (5.4) | 0.69% | — | Jenkins JOB Configuration History | 23/8/2022 | 17/6/2026 | Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names. | |
| Modificada | Alta (8.8) | 80% | — | Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+3 | 10/8/2022 | 17/6/2026 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution. | |
| Analizada | Alta (7.5) | 7.3% | 💥 Exploit | Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+3 | 10/8/2022 | 17/6/2026 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs. | |
| Modificada | Media (4.3) | 0.40% | — | Jenkins JOB Configuration History | 27/7/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations. | |
| Modificada | Alta (8.2) | 2.9% | — | Zohocorp Manageengine OpmanagerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Firewall Analyzer | 18/7/2022 | 17/6/2026 | ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine. | |
| Modificada | Crítica (9.8) | 45% | 💥 PoC | Apache Commons ConfigurationNetapp SnapcenterDebian Linux | 6/7/2022 | 17/6/2026 | Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation.… | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Xpath Configuration Viewer | 30/6/2022 | 17/6/2026 | A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to create and delete XPath expressions. | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Xpath Configuration Viewer | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers to create and delete XPath expressions. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Xpath Configuration Viewer | 30/6/2022 | 17/6/2026 | A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer page. | |
| Modificada | Alta (7.5) | 1.3% | — | HPE Nonstop Distributed Systems Management / Software Configuration Manager | 28/6/2022 | 17/6/2026 | A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. HPE has provided a software update to resolve this vulnerability in HPE NonStop DSM/SCM. | |
| Modificada | Alta (7.8) | 0.92% | — | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+6 | 15/6/2022 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 0.34% | — | Bakerhughes Bentley Nevada 3500 System 1 6.X (3060/00) FirmwareBakerhughes Bentley Nevada 3500 System 1 (3072/xx) FirmwareBakerhughes Bentley Nevada 3500 System 1 (3071/xx) FirmwareBakerhughes Bentley Nevada 3500/22m (288055-01) Firmware+1 | 25/5/2022 | 17/6/2026 | The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior)… | |
| Modificada | Crítica (9.8) | 0.85% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+25 | 19/5/2022 | 17/6/2026 | Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,… | |
| Modificada | Media (6.8) | 0.79% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+8 | 5/5/2022 | 17/6/2026 | On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the… | |
| Modificada | Alta (7.2) | 1.5% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security ManagerF5 Big-ip Guided Configuration | 5/5/2022 | 17/6/2026 | On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions,… | |
| Modificada | Media (6.1) | 0.54% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Guided Configuration | 5/5/2022 | 17/6/2026 | On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of F5 BIG-IP Guided Configuration that allows an attacker to execute JavaScript… | |
| Modificada | Media (6.5) | 0.41% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security ManagerF5 Big-ip Guided Configuration | 5/5/2022 | 17/6/2026 | On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administrator role privilege may be able to bypass Appliance mode restrictions… | |
| Modificada | Crítica (9.1) | 0.87% | — | Johnsoncontrols Metasys System Configuration Tool | 22/4/2022 | 17/6/2026 | The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request. | |
| Modificada | Alta (7.8) | 0.85% | — | Microsoft Endpoint Configuration Manager | 15/4/2022 | 17/6/2026 | Microsoft Endpoint Configuration Manager Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 1.1% | — | Cisco Redundancy Configuration Manager | 17/2/2022 | 17/6/2026 | A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS Software could allow an unauthenticated, remote attacker to cause the checkpoint manager process to restart upon receipt of malformed TCP data. This vulnerability is due to improper input… | |
| Modificada | Crítica (9.8) | 2.3% | — | Mitsubishielectric CW ConfiguratorMitsubishielectric FR Configurator2Mitsubishielectric GX Works2Mitsubishielectric GX Works3+16 | 11/2/2022 | 17/6/2026 | Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code. |