Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
1620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.87% | — | Nvidia Base Command ManagerAI | 23/11/2024 | 17/6/2026 | NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Modificada | Alta (7.8) | 0.10% | — | 2N Access Commander | 5/11/2024 | 17/6/2026 | In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code execution with root permissions. | |
| Modificada | Alta (7.2) | 0.35% | — | 2N Access Commander | 5/11/2024 | 17/6/2026 | In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalate their privileges and gain root access to the system. | |
| Modificada | Alta (7.2) | 0.95% | — | 2N Access Commander | 5/11/2024 | 17/6/2026 | In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potentially achieve arbitrary remote code execution. This vulnerability cannot be exploited by users with lower privilege roles. | |
| Aplazada | Alta (7.5) | 0.57% | — | Command Block IDEAI | 21/10/2024 | 17/6/2026 | In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files used by the game when installed on a dedicated server. | |
| Analizada | Media (4.3) | 0.44% | — | Oracle Enterprise Command Center Framework | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Media (6.5) | 0.57% | — | Netapp Oncommand InsightOracle Mysql Connector/odbc | 15/10/2024 | 18/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… | |
| Analizada | Crítica (9.1) | 1.6% | — | Microsoft Azure Command-line InterfaceMicrosoft Azure Service Connector | 8/10/2024 | 17/6/2026 | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | |
| Aplazada | Crítica (9.8) | 0.42% | — | Fujian Kelixin Communication Command AND Dispatch PlatformAI | 8/10/2024 | 17/6/2026 | Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php. | |
| Analizada | Media (4.3) | 0.18% | — | IBM Cognos Command Center | 26/9/2024 | 17/6/2026 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device. | |
| Aplazada | Alta (8) | 0.60% | — | Command Centre ServerAICommand Centre WorkstationsAI | 11/9/2024 | 17/6/2026 | Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre Workstations 9.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vEL9.00.2168 (MR4),… | |
| Modificada | Alta (7.5) | 0.38% | — | Keyfactor Command | 20/8/2024 | 17/6/2026 | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Keyfactor CommandAI | 20/8/2024 | 17/6/2026 | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges. | |
| Analizada | Media (4.3) | 0.57% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 20/8/2024 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: | |
| Analizada | Alta (7.5) | 0.38% | — | Dell Alienware UpdateDell Command UpdateDell Update | 6/8/2024 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | |
| Aplazada | Alta (7.2) | 1.1% | — | SSH Captive Command ShellAI | 26/7/2024 | 17/6/2026 | A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads. | |
| Modificada | Alta (7.8) | 0.25% | — | Mikekazakov Nimble Commander | 26/7/2024 | 17/6/2026 | Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute system-level commands as the root user, such… | |
| Analizada | Alta (7.4) | 1.1% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+6 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Modificada | Media (4.8) | 0.86% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+4 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Baja (3.7) | 1.1% | — | Oracle JDKOracle JREOracle GraalvmNetapp Oncommand Workflow Automation | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23; Oracle GraalVM Enterprise Edition: 20.3.14 and 21.3.10. Difficult to exploit vulnerability allows… | |
| Analizada | Media (4.8) | 0.94% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+6 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Baja (3.7) | 1.3% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+5 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Baja (3.7) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+5 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Aplazada | Baja (3.3) | 0.15% | — | Gallagher Command CentreAI | 11/7/2024 | 17/6/2026 | Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker limited ability to modify Command Centre log files. This issue affects: Gallagher Command Centre v9.10 prior to vEL9.10.1268 (MR1). | |
| Modificada | Alta (7.8) | 0.14% | — | Dell Alienware Command Center | 10/7/2024 | 17/6/2026 | Dell Alienware Command Center, version 5.7.3.0 and prior, contains an improper access control vulnerability. A low privileged attacker could potentially exploit this vulnerability, leading to denial of service on the local system and information disclosure. |