Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1785 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.59% | — | Veritas Arctera Data InsightAI | 30/12/2024 | 17/6/2026 | Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks. | |
| Analizada | Crítica (9.8) | 0.34% | — | IBM Engineering Lifecycle Optimization - Engineering Insights | 25/12/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser. | |
| Analizada | Media (5.3) | 0.38% | — | IBM Engineering Lifecycle Optimization - Engineering Insights | 25/12/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Aplazada | Media (6.1) | 0.24% | — | Monitorapp Application Insight WEB Application FirewallAI | 20/12/2024 | 17/6/2026 | A reflected cross-site scripting vulnerability in MONITORAPP Application Insight Web Application Firewall (AIWAF) <= 4.1.6 and <=5.0 was identified on the subpage `/process_management/process_status.xhr.php`. This vulnerability allows an attacker to inject malicious scripts that execute in the context of the victim's… | |
| Aplazada | Alta (8.8) | 0.79% | 💥 PoC | Quietly InsightsAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue affects Quietly Insights: from n/a through <= 1.2.2. | |
| Aplazada | Media (5.3) | 0.34% | — | Rapid7 Insight PlatformAI | 11/12/2024 | 17/6/2026 | Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker can successfully update the password policy in the platform settings as a standard user by crafting an API (the functionality was not possible… | |
| Analizada | Media (6.7) | 0.17% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Analizada | Crítica (9.8) | 0.76% | — | Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+1 | 10/12/2024 | 17/6/2026 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and… | |
| Aplazada | Media (5.3) | 0.37% | — | Wpsight WpcasaAI | 6/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WPSight WPCasa wpcasa allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPCasa: from n/a through <= 1.2.13. | |
| Modificada | Crítica (9.8) | 56% | — | HPE Insight Remote Support | 27/11/2024 | 17/6/2026 | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. | |
| Analizada | Alta (7.5) | 84% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Analizada | Alta (7.5) | 47% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Analizada | Crítica (9.8) | 0.72% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code. | |
| Analizada | Alta (7.5) | 1.5% | — | HPE Insight Remote Support | 26/11/2024 | 17/6/2026 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | |
| Aplazada | Media (6.4) | 0.25% | — | Elfsight Telegram Chat CCAI | 18/11/2024 | 17/6/2026 | The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Analizada | Alta (8.2) | 0.70% | — | IBM Engineering Lifecycle Optimization - Engineering Insights | 15/11/2024 | 17/6/2026 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Alta (7) | 0.24% | — | Microfocus Arcsight Management CenterMicrofocus Arcsight Platform | 8/11/2024 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited. | |
| Analizada | Media (6.5) | 0.57% | 💥 PoC | Netapp Oncommand InsightOracle Mysql Connector/odbc | 15/10/2024 | 18/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… | |
| Aplazada | Crítica (9.8) | 1.0% | — | ElsightAI | 6/10/2024 | 17/6/2026 | Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |
| Modificada | Media (6.1) | 0.75% | — | Veritas Data Insight | 4/10/2024 | 17/6/2026 | An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user. | |
| Analizada | Alta (8.6) | 0.29% | — | Cisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could… | |
| Analizada | Alta (8.6) | 0.29% | — | Cisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log… | |
| Analizada | Media (5.3) | 0.36% | — | Codesupply Sight | 26/9/2024 | 17/6/2026 | The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to expose private, pending,… | |
| Analizada | Crítica (9.8) | 0.29% | — | Dell Insightiq | 10/9/2024 | 17/6/2026 | Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (4.4) | 0.15% | — | Dell Insightiq | 10/9/2024 | 17/6/2026 | Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |