Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
678 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.16% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 11/3/2026 | 17/6/2026 | Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (7.2) | 0.71% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of… | |
| Analizada | Crítica (9) | 0.42% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the… | |
| Analizada | Alta (8.1) | 18% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the… | |
| Aplazada | Media (5.5) | 0.09% | — | Cisco Application Policy Infrastructure ControllerAI | 25/2/2026 | 17/6/2026 | A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have valid… | |
| Analizada | Media (6.1) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 4/2/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP… | |
| Analizada | Media (4.8) | 0.21% | — | Cisco Prime Infrastructure | 4/2/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the web-based management interface does not… | |
| Aplazada | Media (5.5) | 0.40% | — | Risesoft Y9 Digital-infrastructureAI | 17/1/2026 | 17/6/2026 | A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (4.8) | 0.26% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists… | |
| Aplazada | Alta (7.1) | 0.22% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 24/12/2025 | 17/6/2026 | Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Aplazada | Alta (8.2) | 0.20% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 24/12/2025 | 17/6/2026 | Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Analizada | Alta (7.8) | 0.10% | — | Zoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 17/6/2026 | Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Analizada | Alta (7.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 17/6/2026 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 17/6/2026 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (6.5) | 0.10% | — | Zoom Meeting Software Development KITZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 17/6/2026 | Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access. | |
| Analizada | Media (6.5) | 0.13% | — | Zoom Workplace Virtual Desktop Infrastructure | 13/11/2025 | 17/6/2026 | Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access. | |
| Analizada | Alta (7.5) | 0.32% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Analizada | Alta (8.1) | 0.33% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Analizada | Crítica (9.8) | 0.47% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (6.5) | 0.33% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via… | |
| Analizada | Media (5.4) | 0.24% | — | Oracle Financial Services Analytical Applications Infrastructure | 21/10/2025 | 30/9/2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Analizada | Media (6.5) | 1.8% | — | Zoom Meeting Software Development KITZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 15/10/2025 | 17/6/2026 | Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Aplazada | Alta (8.4) | 0.47% | — | CA Technologies DX Unified Infrastructure ManagementAICA Technologies Nimsoft UIMAI | 1/10/2025 | 17/6/2026 | DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system. | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa💥 PoC | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… |