Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 2.5% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/. | |
| Modificada | Alta (8.8) | 6.1% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. | |
| Modificada | Alta (8.8) | 7.2% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter. | |
| Modificada | Crítica (9.8) | 5.6% | — | Trendmicro Threat Discovery Appliance | 28/4/2017 | 17/6/2026 | Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value. | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Tivoli Application Dependency Discovery Manager | 14/4/2017 | 17/6/2026 | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Media (4.3) | 0.83% | — | IBM Tivoli Application Dependency Discovery Manager | 14/4/2017 | 17/6/2026 | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539. | |
| Modificada | Media (6.5) | 1.4% | — | IBM Tivoli Application Dependency Discovery Manager | 14/4/2017 | 17/6/2026 | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538. | |
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Trendmicro Threat Discovery Appliance | 12/4/2017 | 17/6/2026 | On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS. | |
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Trendmicro Threat Discovery Appliance | 12/4/2017 | 17/6/2026 | A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface. | |
| Modificada | Alta (7.2) | 7.8% | 💥 Exploit | Trend Micro Deep Discovery Inspector | 30/6/2016 | 17/6/2026 | hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header. | |
| Modificada | Alta (8.8) | 2.4% | — | HP Discovery AND Dependency Mapping Inventory | 8/6/2016 | 17/6/2026 | HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | |
| Modificada | Crítica (9.8) | 4.7% | — | HP Universal Cmbd FoundationHP Universal Cmbd Configuration ManagerHP Universal Discovery | 8/6/2016 | 17/6/2026 | HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. | |
| Modificada | Media (5.5) | 2.7% | — | Trendmicro Deep Discovery Inspector | 23/8/2015 | 17/6/2026 | Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information or change the configuration via a direct request to the (1)… | |
| Modificada | Media (4.3) | 2.7% | — | Trendmicro Deep Discovery Inspector | 23/8/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allow remote attackers to inject arbitrary web script or HTML via… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Discovery Xr656Gehealthcare Discovery Xr656 G2 | 4/8/2015 | 17/6/2026 | GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser user, and (3) #superxr for the root user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Discovery NM 750b | 4/8/2015 | 17/6/2026 | GE Healthcare Discovery NM 750b has a password of 2getin for the insite account for (1) Telnet and (2) FTP, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Discovery 530c Firmware | 4/8/2015 | 16/6/2026 | GE Healthcare Discovery 530C has a password of #bigguy1 for the (1) acqservice user and (2) wsservice user of the Xeleris System, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. | |
| Modificada | Alta (10) | 1.6% | — | Gehealthcare Discovery VH | 4/8/2015 | 16/6/2026 | GE Healthcare Discovery VH has a default password of (1) interfile for the ftpclient user of the Interfile server or (2) "2" for the LOCAL user of the FTP server for the Codonics printer, which has unspecified impact and attack vectors. | |
| Modificada | Media (5) | 1.2% | — | IBM Endpoint Manager FamilyIBM License Metric ToolIBM Tivoli Asset Discovery FOR Distributed | 25/5/2015 | 17/6/2026 | Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a… | |
| Modificada | Media (5) | 1.2% | — | IBM Endpoint Manager FamilyIBM License Metric ToolIBM Tivoli Asset Discovery FOR Distributed | 25/5/2015 | 17/6/2026 | Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a… | |
| Modificada | Media (6.4) | 1.8% | — | IBM License Metric ToolIBM Tivoli Asset Discovery FOR Distributed | 20/5/2015 | 17/6/2026 | The server in IBM License Metric Tool 7.2.2 before IF15 and 7.5 before IF24 and Tivoli Asset Discovery for Distributed 7.2.2 before IF15 and 7.5 before IF24 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction… | |
| Modificada | Baja (3.5) | 0.94% | — | IBM Tivoli Application Dependency Discovery Manager | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.0 through 7.2.1.6 and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Baja (3.5) | 1.0% | — | IBM Tivoli Application Dependency Discovery Manager | 31/10/2014 | 17/6/2026 | IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sensitive database information via a crafted URL. | |
| Modificada | Media (5) | 1.9% | — | IBM Tivoli Application Dependency Discovery Manager | 29/10/2014 | 17/6/2026 | Directory traversal vulnerability in BIRT-viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to read arbitrary files via unspecified vectors. |