Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

678 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.16%—Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure11/3/202617/6/2026
Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaAlta (7.2)0.71%—Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform25/2/202617/6/2026
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of…
AnalizadaCrítica (9)0.42%—Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform25/2/202617/6/2026
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the…
AnalizadaAlta (8.1)18%⚠ Explotación activaVmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform25/2/202617/6/2026
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the…
AplazadaMedia (5.5)0.09%—Cisco Application Policy Infrastructure ControllerAI25/2/202617/6/2026
A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have valid…
AnalizadaMedia (6.1)0.22%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure4/2/202629/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP…
AnalizadaMedia (4.8)0.21%—Cisco Prime Infrastructure4/2/202629/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management interface does not…
AplazadaMedia (5.5)0.40%—Risesoft Y9 Digital-infrastructureAI17/1/202617/6/2026
A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The…
AnalizadaMedia (4.8)0.26%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure15/1/202617/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists…
AplazadaAlta (7.1)0.22%—Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI24/12/202517/6/2026
Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00.
AplazadaAlta (8.2)0.20%—Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI24/12/202517/6/2026
Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00.
AnalizadaAlta (7.8)0.10%—Zoom Workplace Virtual Desktop Infrastructure13/11/202517/6/2026
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
AnalizadaAlta (7.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/202517/6/2026
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaAlta (7.5)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+113/11/202517/6/2026
Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (6.5)0.10%—Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure13/11/202517/6/2026
Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.
AnalizadaMedia (6.5)0.13%—Zoom Workplace Virtual Desktop Infrastructure13/11/202517/6/2026
Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
AnalizadaAlta (7.5)0.32%—Oracle Financial Services Analytical Applications Infrastructure21/10/202517/6/2026
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network…
AnalizadaAlta (8.1)0.33%—Oracle Financial Services Analytical Applications Infrastructure21/10/202517/6/2026
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via…
AnalizadaCrítica (9.8)0.47%—Oracle Financial Services Analytical Applications Infrastructure21/10/202517/6/2026
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via…
AnalizadaAlta (8.6)0.41%—Oracle Financial Services Analytical Applications Infrastructure21/10/202517/6/2026
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via…
AnalizadaMedia (6.5)0.33%—Oracle Financial Services Analytical Applications Infrastructure21/10/202517/6/2026
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via…
AnalizadaMedia (5.4)0.24%—Oracle Financial Services Analytical Applications Infrastructure21/10/202530/9/2026
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via…
AnalizadaMedia (6.5)1.8%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure15/10/202517/6/2026
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
AplazadaAlta (8.4)0.47%—CA Technologies DX Unified Infrastructure ManagementAICA Technologies Nimsoft UIMAI1/10/202517/6/2026
DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.
AnalizadaAlta (7.8)8.4%⚠ Explotación activa💥 PoCVmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+429/9/202517/6/2026
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the…