Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

591 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.52%—Johnsoncontrols Openblue Enterprise Manager Data Collector18/5/202317/6/2026
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
ModificadaAlta (7.5)1.1%💥 PoCJohnsoncontrols Openblue Enterprise Manager Data Collector18/5/202317/6/2026
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
ModificadaMedia (4.3)0.38%—Snowsoftware Snow License Manager17/5/202317/6/2026
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data.
ModificadaAlta (8.1)0.98%—Reprisesoftware Reprise License Manager20/1/20239/7/2026
Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to overwrite any file the on the server.
ModificadaMedia (6.5)0.70%—Reprisesoftware Reprise License Manager20/1/20239/7/2026
CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that allows remote attackers to inject arbitrary HTTP headers.
ModificadaMedia (6.5)0.60%—Reprisesoftware Reprise License Manager20/1/20239/7/2026
An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function.
ModificadaCrítica (9.8)1.5%—Siemens Automation License Manager10/1/202317/6/2026
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected component does not correctly validate the root path on folder related operations, allowing to modify files…
ModificadaAlta (7.5)0.97%—Siemens Automation License Manager10/1/202317/6/2026
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input without authentication. This could allow…
AnalizadaMedia (6.1)2.5%💥 ExploitReprisesoftware Reprise License Manager29/12/202217/6/2026
XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.
ModificadaAlta (7.5)0.70%—Oracle Enterprise Manager Base Platform18/10/202217/6/2026
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise…
ModificadaCrítica (9.8)100%💥 ExploitApache Commons TextNetapp BluexpJuniper Security Threat Response Manager13/10/202217/6/2026
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with…
ModificadaAlta (8.1)1.0%—Oracle Enterprise Manager Base Platform19/7/202217/6/2026
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base…
ModificadaAlta (7.3)0.73%—Oracle Enterprise Manager Base Platform19/7/202217/6/2026
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise…
ModificadaAlta (7.5)1.0%—Wpusermanager WP User Manager17/7/202217/6/2026
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.
ModificadaAlta (7.8)0.23%—Snowsoftware Snow License Manager18/5/202217/6/2026
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.
ModificadaCrítica (9.8)2.2%—Microstrategy Enterprise Manager11/5/202217/6/2026
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for directory traversal.
ModificadaAlta (7.3)83%💥 PoCSiemens Brownfield Connectivity GatewayOpensslDebian LinuxNetapp Active IQ Unified Manager+313/5/202217/6/2026
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the…
ModificadaMedia (6.1)1.3%💥 PoCAntisamy Project AntisamyOracle Enterprise Manager Base PlatformOracle Weblogic Server21/4/202217/6/2026
OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.
ModificadaMedia (4.7)0.74%—Oracle Enterprise Manager Base Platform19/4/202217/6/2026
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base…
ModificadaMedia (6.1)0.51%—Claderaform Calderawp License Manager12/4/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Manager (WordPress plugin) <= 1.2.11.
AnalizadaMedia (5.3)9.3%💥 ExploitReprisesoftware Reprise License Manager9/4/202217/6/2026
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.
AnalizadaMedia (5.4)0.97%—Reprisesoftware Reprise License Manager9/4/202217/6/2026
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.
AnalizadaMedia (6.1)4.9%💥 ExploitReprisesoftware Reprise License Manager9/4/202217/6/2026
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.
ModificadaCrítica (9.1)42%—Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+414/3/202217/6/2026
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
ModificadaCrítica (9.8)28%💥 PoCApache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+414/3/202217/6/2026
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling