Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

416 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)1.0%—Containers CommonRedhat Openshift Container PlatformRedhat Enterprise Linux1/10/202411/8/2026
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a…
AnalizadaMedia (5.4)0.31%—Chetanvaghela Common Tools FOR Site26/9/202417/6/2026
The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
AnalizadaAlta (7.8)0.20%—Hitachi OPS Center Common Services27/8/202417/6/2026
Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.
AnalizadaAlta (7)1.2%—Paloaltonetworks Cortex Xsoar Commonscripts14/8/202417/6/2026
A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.
ModificadaMedia (4.8)0.26%—IBM Common Licensing13/8/202417/6/2026
IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 350348.
AnalizadaAlta (7.5)0.49%—IBM Common Licensing13/8/202417/6/2026
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.
AnalizadaMedia (6.5)0.20%—Hitachi OPS Center Common Services2/7/202417/6/2026
Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00.
AnalizadaAlta (7.3)0.50%—Amoyjs Common1/7/202417/6/2026
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
AnalizadaAlta (7.3)0.52%—Amoyjs Common1/7/202417/6/2026
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
AplazadaMedia (6.3)0.47%—Tada5hi Sp-commonAI1/7/202417/6/2026
Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
ModificadaMedia (6.5)0.21%—Wielebenwir Commonsbooking21/6/202417/6/2026
The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks
ModificadaMedia (4.8)0.33%—Wielebenwir Commonsbooking21/6/202417/6/2026
The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.8)0.36%—Dell Common Event Enabler12/6/202417/6/2026
Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to…
AplazadaAlta (7.7)0.28%—Gehealthcare Common Service DesktopAI14/5/202417/6/2026
Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component
AplazadaMedia (6.2)0.28%—Gehealthcare Common Service DesktopAI14/5/202417/6/2026
Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component
AplazadaCrítica (9.8)1.2%—Andrei-tatar Nora-firebase-commonAI18/4/202417/6/2026
An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method.
AnalizadaAlta (7.5)0.64%—IBM Common Cryptographic Architecture26/3/202417/6/2026
IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602.
AnalizadaBaja (3.7)0.45%—IBM Common Cryptographic Architecture26/3/202417/6/2026
Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack. IBM X-Force ID: 257676.
AnalizadaMedia (5.4)1.7%—Apache Commons ConfigurationFedoraproject Fedora21/3/202417/6/2026
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.
AnalizadaAlta (7.3)2.1%—Apache Commons ConfigurationFedoraproject FedoraNetapp Ontap ToolsNetapp Snapcenter21/3/202417/6/2026
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.
AnalizadaAlta (7.5)0.55%—Common-services SO Flexibilite3/3/202417/6/2026
An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.
AnalizadaAlta (7.8)0.19%—Aveva Platform Common Services29/2/202417/6/2026
The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL.
AnalizadaMedia (5.9)0.39%—Common-services SO Flexibilite27/2/202417/6/2026
In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.
AnalizadaAlta (7.5)0.80%—Linuxfoundation Backstage Backend-common23/2/202417/6/2026
`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and 0.19.10, paths checks with the `resolveSafeChildPath` utility were not exhaustive enough, leading to risk of…
AnalizadaBaja (3.3)0.19%—IBM Common Licensing20/2/202417/6/2026
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.
Orbitaley — Vulnerabilidades