Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
–

4321 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.56%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+163/5/202317/6/2026
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (7.8)0.43%—Linux KernelNetapp HCI Baseboard Management Controller1/5/202317/6/2026
A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past…
ModificadaMedia (6.1)0.58%—Controlid Rhid29/4/202317/6/2026
A vulnerability classified as problematic has been found in Control iD RHiD 23.3.19.0. Affected is an unknown function of the file /v2/#/add/department. The manipulation of the argument Name leads to cross site scripting. It is possible to launch the attack remotely. VDB-227718 is the identifier assigned to this…
ModificadaCrítica (9.8)1.1%—Thecontrolgroup Voyager26/4/202317/6/2026
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.
ModificadaAlta (7)0.36%—Linux KernelNetapp HCI Baseboard Management Controller24/4/202317/6/2026
A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.
ModificadaAlta (8.8)0.47%—Linuxfoundation Kubewarden-controller19/4/202317/6/2026
An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount kubewarden-controller This issue affects: SUSE kubewarden kubewarden-controller versions prior to 1.6.0.
ModificadaMedia (5.3)1.3%💥 PoCEclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+218/4/202317/6/2026
Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cookie parsing mechanism. If Jetty sees a cookie VALUE that starts with `"` (double quote), it will…
ModificadaAlta (8.8)0.84%—Schneider-electric Ecostruxure Control Expert18/4/202317/6/2026
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)
ModificadaMedia (5.5)0.15%—Schneider-electric Ecostruxure Control Expert18/4/202317/6/2026
A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above)
ModificadaMedia (6.1)0.36%—Assaabloy Control ID Idsecure14/4/202317/6/2026
A vulnerability has been found in Control iD iDSecure 4.7.29.1 and classified as problematic. This vulnerability affects unknown code of the component Dispositivos Page. The manipulation of the argument IP-DNS leads to cross site scripting. The attack can be initiated remotely. VDB-225922 is the identifier assigned to…
ModificadaCrítica (9.8)0.50%—Assaabloy Control ID Rhid14/4/202317/6/2026
A vulnerability, which was classified as problematic, was found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/customerdb/operator.svc/a of the component Edit Handler. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The…
ModificadaAlta (7.2)0.96%—Atos Unify Openscape BCFAtos Unify Openscape BranchAtos Unify Openscape Session Border Controller14/4/202317/6/2026
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.
ModificadaCrítica (9.8)0.46%—ABB MY Control System6/4/202317/6/2026
Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My Control System (on-premise) application,…
ModificadaAlta (8)0.25%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
ModificadaCrítica (9.8)1.2%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions.
ModificadaCrítica (9.8)0.77%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation…
ModificadaMedia (6.1)0.83%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.
ModificadaCrítica (9.8)0.89%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without providing valid credentials. A threat actor who successfully…
ModificadaAlta (7.5)1.5%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
ModificadaCrítica (9.8)1.6%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script.
ModificadaCrítica (9.8)18%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.
ModificadaAlta (7.5)0.65%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an attacker to hijack a session by predicting the session id and gain unauthorized access to the product.
ModificadaMedia (5.4)0.35%—Sauter-controls Ey-as525f001 Firmware27/3/202317/6/2026
A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context of the targeted privileged users.
ModificadaMedia (6.5)0.62%—Sauter-controls Ey-as525f001 Firmware27/3/202317/6/2026
An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.
ModificadaMedia (6.1)0.52%—Sauter-controls Ey-as525f001 Firmware27/3/202317/6/2026
An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScript (JS) payload in the target’s security context.