Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

215 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.24%—Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+2026/7/202217/6/2026
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.
ModificadaAlta (7.8)0.22%—Emerson Deltav Distributed Control System26/7/202217/6/2026
The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP);…
ModificadaAlta (7.5)1.3%—HPE Nonstop Distributed Systems Management / Software Configuration Manager28/6/202217/6/2026
A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. HPE has provided a software update to resolve this vulnerability in HPE NonStop DSM/SCM.
ModificadaMedia (5.4)0.52%—Tibco BPM EnterpriseTibco BPM Enterprise Distribution FOR Silver Fabric17/5/202217/6/2026
The Workspace client component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric contains difficult to exploit Reflected Cross Site Scripting (XSS) vulnerabilities that allow low privileged attackers with network access to execute scripts targeting the affected…
ModificadaCrítica (9.8)48%💥 ExploitNarnoo Distributor Project Narnoo Distributor28/3/202217/6/2026
The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results in the disclosure of arbitrary files as…
ModificadaMedia (6.1)1.5%—Smartbear Swagger-ui-dist11/3/202217/6/2026
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the…
ModificadaMedia (5.5)0.19%—Emerson Deltav WorkstationEmerson Deltav Distributed Control System28/1/202217/6/2026
A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.
ModificadaAlta (8)0.77%—Schneider-electric Rack Power Distribution Unit With Network Management Card 2 FirmwareSchneider-electric Rack Power Distribution Unit With Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. Affected Products: AP7xxxx and AP8xxx with NMC2 (V6.9.6 or…
ModificadaAlta (7.2)1.7%—Genesys Intelligent Workload Distribution Manager8/12/202117/6/2026
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or…
ModificadaAlta (7.2)1.7%—Genesys Intelligent Workload Distribution Manager8/12/202117/6/2026
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command execution is possible depending on the…
ModificadaMedia (5)2.2%—Linuxfoundation Open Container Initiative Distribution SpecificationLinuxfoundation Open Container Initiative Image Format SpecificationFedoraproject Fedora17/11/202117/6/2026
The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both…
ModificadaMedia (5.5)0.22%—Intel Distribution OF Openvino Toolkit17/11/202117/6/2026
Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.22%—Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+1012/10/202117/6/2026
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.
ModificadaCrítica (9.8)2.5%—Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+1012/10/202117/6/2026
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.
ModificadaAlta (7.5)1.9%—Eclipse Cyclone Data Distribution Service23/8/202117/6/2026
A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
ModificadaAlta (7.5)1.9%—Eclipse Cyclone Data Distribution Service23/8/202117/6/2026
A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
ModificadaMedia (6.5)9.9%—Apache TomcatOracle Communications Cloud Native Core PolicyOracle Communications Diameter Signaling RouterOracle Communications Pricing Design Center+312/7/202117/6/2026
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
ModificadaAlta (7.1)0.89%—Amazon Open Distro6/5/202117/6/2026
An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.
ModificadaAlta (7.5)2.0%—Cumulative-distribution-function Project Cumulative-distribution-function30/4/202117/6/2026
cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution function from data array of x values. In versions prior to 2.0.0 apps using this library on improper data may crash or go into an infinite-loop. In the case of a nodejs server-app using this library…
ModificadaAlta (7.5)11%—Debian LinuxISC BindFedoraproject FedoraNetapp Active IQ Unified Manager+1229/4/202117/6/2026
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw…
ModificadaAlta (8.1)0.99%—Oracle Labor Distribution22/4/202117/6/2026
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks…
ModificadaAlta (7.8)0.23%—Tibco Messaging - Eclipse Mosquitto Distribution - Bridge14/4/202117/6/2026
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on…
ModificadaAlta (7.8)0.23%—Tibco Messaging - Eclipse Mosquitto Distribution - Core14/4/202117/6/2026
The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some…
ModificadaCrítica (9.8)1.2%—Tibco API Exchange GatewayTibco API Exchange Gateway Distribution23/3/202117/6/2026
The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack…
ModificadaMedia (5.5)0.34%—Linux KernelOracle Tekelec Platform Distribution10/3/202117/6/2026
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.
Orbitaley — Vulnerabilidades