Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.3%—Genivia GsoapOracle Communications Diameter Signaling RouterOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+225/3/202117/6/2026
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.8)1.7%—Swift Development Environment Project Swift Development Environment18/3/202117/6/2026
The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted sourcekit-lsp.serverPath, swift.languageServerPath, swift.path.sourcekite, swift.path.sourcekiteDockerMode,…
ModificadaCrítica (9.8)6.0%💥 PoCPyyamlOracle Communications Cloud Native Core Network Function Cloud Native Environment9/2/202117/6/2026
A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this…
ModificadaCrítica (9.1)6.7%—Cryptography.io CryptographyFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment7/2/202117/6/2026
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
ModificadaMedia (5.3)1.1%—TI Code Composer Studio Intgrated Development Environment26/1/202117/6/2026
jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.
ModificadaCrítica (9.8)23%—PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+619/1/202117/6/2026
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
ModificadaMedia (5.9)2.5%—Cryptography.io CryptographyOracle Communications Cloud Native Core Network Function Cloud Native Environment11/1/202117/6/2026
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
ModificadaMedia (6.5)1.5%—Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment5/1/202117/6/2026
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by sending specially crafted UDP requests.
ModificadaMedia (6.7)0.17%—Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment5/1/202117/6/2026
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in a system file. A local authenticated attacker with access to the system files may use the…
ModificadaMedia (6.7)0.26%—Dell EMC Unity Operating EnvironmentDell EMC Unity VSA Operating EnvironmentDell EMC Unity XT Operating Environment5/1/202117/6/2026
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (including the Unisphere admin privilege user) password is stored in a plain text in multiple log files. A local authenticated attacker with access to the log files may use the…
ModificadaMedia (5.9)7.1%💥 PoCOpensslDebian LinuxFedoraproject FedoraOracle API Gateway+408/12/202017/6/2026
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both…
ModificadaCrítica (9.8)8.3%—PythonFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment22/10/202017/6/2026
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
ModificadaMedia (6.5)2.3%—Python Urllib3Canonical Ubuntu LinuxDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+130/9/202017/6/2026
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
ModificadaAlta (7.5)4.5%—Ua-parser-js Project Ua-parser-jsOracle Communications Cloud Native Core Network Function Cloud Native Environment16/9/202017/6/2026
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
ModificadaAlta (7.5)3.0%—Pypa PIPOpensuse LeapDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+14/9/202017/6/2026
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
ModificadaMedia (6.5)3.0%—Xmlsoft Libxml2Debian LinuxFedoraproject FedoraOpensuse Leap+144/9/202017/6/2026
GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
ModificadaMedia (6.7)1.2%—Elasticsearch KibanaOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Peoplesoft Enterprise Peopletools27/7/202017/6/2026
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
ModificadaMedia (4.8)1.1%—Elasticsearch KibanaOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Peoplesoft Enterprise Peopletools27/7/202017/6/2026
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
ModificadaCrítica (9.8)5.4%—PyyamlFedoraproject FedoraOpensuse LeapOracle Communications Cloud Native Core Network Function Cloud Native Environment24/3/202017/6/2026
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this…
ModificadaMedia (6.5)0.85%—Jenkins Parasoft Environment Manager12/2/202017/6/2026
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaCrítica (9.8)20%—Nodejs Node.jsOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle GraalvmDebian Linux+37/2/202017/6/2026
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
ModificadaAlta (7.5)20%—Nodejs Node.jsDebian LinuxOpensuse LeapRedhat Software Collections+67/2/202017/6/2026
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
ModificadaAlta (7.5)1.4%—Dell EMC Unity Operating EnvironmentDell EMC Unity XT Operating EnvironmentDell EMC Unityvsa Operating Environment6/2/202017/6/2026
Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit this vulnerability and cause a Denial of…
ModificadaMedia (5.3)1.2%—Proxmox Virtual Environment27/1/202017/6/2026
Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability
ModificadaAlta (7.5)2.0%—Agendaless WaitressOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian Linux22/1/202017/6/2026
Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Content-Length to 0 internally. If two Content-Length headers are sent…