Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.1% | — | MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+5 | 29/2/2024 | 17/6/2026 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. | |
| Analizada | Media (5.3) | 0.81% | — | MIT Kerberos 5Netapp Active IQ Unified ManagerNetapp Cloud Volumes Ontap MediatorManagement Services FOR Element Software AND Netapp HCI+5 | 29/2/2024 | 17/6/2026 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. | |
| Modificada | Media (5.5) | 0.19% | — | IBM Urbancode DeployIBM Devops Deploy | 6/2/2024 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent. IBM X-Force ID: 279971. | |
| Modificada | Media (5.5) | 0.21% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 3/2/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. | |
| Modificada | Crítica (9.8) | 1.8% | — | Broadcom Symantec Deployment Solutions | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as SYSTEM. | |
| Modificada | Alta (7.5) | 0.54% | — | Pivotal Cloud Foundry DeploymentPivotal Cloud Foundry Routing Release | 12/1/2024 | 17/6/2026 | Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment. | |
| Modificada | Media (6.5) | 0.81% | — | IBM Urbancode Deploy | 20/12/2023 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. IBM X-Force ID: 270799. | |
| Modificada | Media (5.3) | 0.71% | — | IBM Urbancode Deploy | 20/12/2023 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 265510. | |
| Modificada | Media (5.5) | 0.23% | — | IBM Urbancode Deploy | 20/12/2023 | 17/6/2026 | An IBM UrbanCode Deploy Agent 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts. IBM X-Force ID: 265509. | |
| Modificada | Media (4.3) | 0.57% | — | IBM Urbancode Deploy | 19/12/2023 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. IBM X-Force ID: 265512. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Deployment Dashboard | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Alta (7.5) | 0.81% | — | Cisco Emergency ResponderCisco Prime Collaboration DeploymentCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+1 | 4/10/2023 | 17/6/2026 | A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is… | |
| Modificada | Media (6.5) | 0.55% | — | IBM Urbancode Deploy | 4/10/2023 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations could allow an authenticated user to make changes to environment variables due to improper authentication controls. IBM X-Force ID: 263581. | |
| Analizada | Alta (7.8) | 64% | ⚠ Explotación activa💥 Exploit | Netapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+35 | 3/10/2023 | 17/6/2026 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated… | |
| Modificada | Media (5.3) | 0.44% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 8/9/2023 | 17/6/2026 | Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identification value recorded in the logs in foundations. | |
| Modificada | Alta (7.5) | 1.5% | — | Vmware ToolsVmware Open VM ToolsFedoraproject FedoraDebian Linux+1 | 31/8/2023 | 17/6/2026 | A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest… | |
| Modificada | Media (5.5) | 0.64% | — | GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. | |
| Modificada | Media (5.5) | 0.61% | — | GNU BinutilsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. | |
| Modificada | Alta (7.8) | 0.26% | — | Psappdeploytoolkit Powershell APP Deployment Toolkit | 1/8/2023 | 17/6/2026 | In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability in the default configuration may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Crítica (9.8) | 0.57% | — | CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+4 | 25/7/2023 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of… | |
| Modificada | Alta (7.5) | 2.0% | — | ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+2 | 17/7/2023 | 17/6/2026 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | |
| Modificada | Media (5.3) | 0.62% | — | OpensslManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration Utility | 14/7/2023 | 17/6/2026 | Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding… | |
| Modificada | Media (5.9) | 0.58% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing Release | 26/5/2023 | 17/6/2026 | In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and… | |
| Modificada | Media (6.5) | 3.2% | — | Quest Kace Systems Deployment Appliance | 21/5/2023 | 17/6/2026 | There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled… |