Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.3% | — | Genivia GsoapOracle Communications Diameter Signaling RouterOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+2 | 25/3/2021 | 17/6/2026 | A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 1.7% | — | Swift Development Environment Project Swift Development Environment | 18/3/2021 | 17/6/2026 | The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted sourcekit-lsp.serverPath, swift.languageServerPath, swift.path.sourcekite, swift.path.sourcekiteDockerMode,… | |
| Modificada | Crítica (9.8) | 6.0% | 💥 PoC | PyyamlOracle Communications Cloud Native Core Network Function Cloud Native Environment | 9/2/2021 | 17/6/2026 | A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this… | |
| Modificada | Crítica (9.1) | 6.7% | — | Cryptography.io CryptographyFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment | 7/2/2021 | 17/6/2026 | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class. | |
| Modificada | Media (5.3) | 1.1% | — | TI Code Composer Studio Intgrated Development Environment | 26/1/2021 | 17/6/2026 | jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS. | |
| Modificada | Crítica (9.8) | 23% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+6 | 19/1/2021 | 17/6/2026 | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely. | |
| Modificada | Media (5.9) | 2.5% | — | Cryptography.io CryptographyOracle Communications Cloud Native Core Network Function Cloud Native Environment | 11/1/2021 | 17/6/2026 | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext. | |
| Modificada | Media (6.5) | 1.5% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by sending specially crafted UDP requests. | |
| Modificada | Media (6.7) | 0.17% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with access to the system files may use the… | |
| Modificada | Media (6.7) | 0.26% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment | 5/1/2021 | 17/6/2026 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker with access to the log files may use the… | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Crítica (9.8) | 8.3% | — | PythonFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment | 22/10/2020 | 17/6/2026 | In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. | |
| Modificada | Media (6.5) | 2.3% | — | Python Urllib3Canonical Ubuntu LinuxDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+1 | 30/9/2020 | 17/6/2026 | urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116. | |
| Modificada | Alta (7.5) | 4.5% | — | Ua-parser-js Project Ua-parser-jsOracle Communications Cloud Native Core Network Function Cloud Native Environment | 16/9/2020 | 17/6/2026 | The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA. | |
| Modificada | Alta (7.5) | 3.0% | — | Pypa PIPOpensuse LeapDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+1 | 4/9/2020 | 17/6/2026 | The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py. | |
| Modificada | Media (6.5) | 3.0% | — | Xmlsoft Libxml2Debian LinuxFedoraproject FedoraOpensuse Leap+14 | 4/9/2020 | 17/6/2026 | GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. | |
| Modificada | Media (6.7) | 1.2% | — | Elasticsearch KibanaOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Peoplesoft Enterprise Peopletools | 27/7/2020 | 17/6/2026 | In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization. | |
| Modificada | Media (4.8) | 1.1% | — | Elasticsearch KibanaOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Peoplesoft Enterprise Peopletools | 27/7/2020 | 17/6/2026 | Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive. | |
| Modificada | Crítica (9.8) | 5.4% | — | PyyamlFedoraproject FedoraOpensuse LeapOracle Communications Cloud Native Core Network Function Cloud Native Environment | 24/3/2020 | 17/6/2026 | A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this… | |
| Modificada | Media (6.5) | 0.85% | — | Jenkins Parasoft Environment Manager | 12/2/2020 | 17/6/2026 | Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Crítica (9.8) | 20% | — | Nodejs Node.jsOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle GraalvmDebian Linux+3 | 7/2/2020 | 17/6/2026 | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons | |
| Modificada | Alta (7.5) | 20% | — | Nodejs Node.jsDebian LinuxOpensuse LeapRedhat Software Collections+6 | 7/2/2020 | 17/6/2026 | Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate | |
| Modificada | Alta (7.5) | 1.4% | — | Dell EMC Unity Operating EnvironmentDell EMC Unity XT Operating EnvironmentDell EMC Unityvsa Operating Environment | 6/2/2020 | 17/6/2026 | Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit this vulnerability and cause a Denial of… | |
| Modificada | Media (5.3) | 1.2% | — | Proxmox Virtual Environment | 27/1/2020 | 17/6/2026 | Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability | |
| Modificada | Alta (7.5) | 2.0% | — | Agendaless WaitressOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian Linux | 22/1/2020 | 17/6/2026 | Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Content-Length to 0 internally. If two Content-Length headers are sent… |