Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

4643 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaAlta (8)0.25%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
ModificadaCrítica (9.8)1.2%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions.
ModificadaCrítica (9.8)0.77%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot be changed through any normal operation…
ModificadaMedia (6.1)0.83%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.
ModificadaCrítica (9.8)0.89%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user account without providing valid credentials. A threat actor who successfully…
ModificadaAlta (7.5)1.5%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and disclose sensitive and system information.
ModificadaCrítica (9.8)1.6%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script.
ModificadaCrítica (9.8)18%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.
ModificadaAlta (7.5)0.65%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This may allow an attacker to hijack a session by predicting the session id and gain unauthorized access to the product.
ModificadaAlta (7.8)1.9%💥 PoCLinux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+927/3/202317/6/2026
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
ModificadaAlta (7.8)0.90%—X.org X ServerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux AUS+1427/3/202317/6/2026
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote…
ModificadaMedia (6.5)1.1%—Ladybirdweb Faveo Servicedesk24/3/202317/6/2026
Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.
ModificadaCrítica (9.1)3.1%—Zohocorp Manageengine Adselfservice Plus23/3/202317/6/2026
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
ModificadaMedia (5.3)0.82%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password. The attack complexity is high since a successful exploitation requires to…
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
ModificadaMedia (5.4)0.48%—Adobe Experience ManagerAdobe Experience Manager Cloud Service22/3/202317/6/2026
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.