Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.73% | — | Hidglobal Omnikey 5427 FirmwareHidglobal Omnikey 5127 Firmware | 24/3/2021 | 17/6/2026 | HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the device. An attacker could exploit this… | |
| Modificada | Media (5.4) | 0.56% | — | IBM Tivoli Netcool/omnibus Webgui | 11/3/2021 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Alta (7.7) | 1.3% | — | Omniauth-apple Project Omniauth-apple | 8/12/2020 | 17/6/2026 | omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during authentication. This vulnerability impacts applications using the omniauth-apple strategy of OmniAuth and using the info.email field of… | |
| Modificada | Crítica (9.8) | 1.4% | — | IllumosJoyent SmartosOmniosce Omnios | 26/10/2020 | 17/6/2026 | An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c. | |
| Modificada | Crítica (9.1) | 0.80% | — | Omniauth-auth0 | 21/10/2020 | 17/6/2026 | omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Improper validation of the JWT token signature can allow an attacker to bypass authentication and authorization. You are affected by this vulnerability if all of the… | |
| Modificada | Alta (8.2) | 0.60% | — | FreebsdOmniosce OmniosOpenindianaNetapp Clustered Data Ontap | 25/9/2020 | 17/6/2026 | bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP. | |
| Modificada | Media (4.3) | 0.49% | — | IBM Tivoli Netcool/omnibus | 18/3/2020 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174910. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Tivoli Netcool/omnibus | 3/3/2020 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174909. | |
| Modificada | Baja (2.4) | 0.34% | — | IBM Tivoli Netcool/omnibus | 3/3/2020 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174908. | |
| Modificada | Media (5.4) | 0.56% | — | IBM Tivoli Netcool/omnibus | 3/3/2020 | 17/6/2026 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174907. | |
| Modificada | Crítica (9.8) | 2.4% | — | Omniauth-weibo-oauth2 Project Omniauth-weibo-oauth2 | 7/2/2020 | 17/6/2026 | The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected. | |
| Modificada | Crítica (9.8) | 7.2% | — | HP Simplivity 380 Gen9 FirmwareHP Simplivity 380 Gen10 G FirmwareHP Simplivity 380 Gen10 FirmwareHP Simplivity 2600 Gen10 Firmware+4 | 3/1/2020 | 17/6/2026 | A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. An API is used to execute a command… | |
| Modificada | Alta (7.5) | 1.5% | — | HP Simplivity 380 Gen9 FirmwareHP Simplivity 380 Gen10 G FirmwareHP Simplivity 380 Gen10 FirmwareHP Simplivity 2600 Gen10 Firmware+4 | 3/1/2020 | 17/6/2026 | A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. Two now deprecated APIs run as… | |
| Modificada | Crítica (9.8) | 13% | — | Al-enterprise Omnivista 4760 | 27/12/2019 | 17/6/2026 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file… | |
| Modificada | Alta (7.2) | 5.8% | — | Al-enterprise Omnivista 8770 | 27/12/2019 | 17/6/2026 | An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM. | |
| Modificada | Alta (7.5) | 2.7% | — | Al-enterprise Omnivista 4760Al-enterprise Omnivista 8770 | 27/12/2019 | 17/6/2026 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session files. Every session file contains the administrative LDAP credentials encoded in a reversible… | |
| Modificada | Alta (7.5) | 1.8% | — | Omniauth-facebook Project Omniauth-facebook | 11/12/2019 | 16/6/2026 | RubyGem omniauth-facebook has an access token security vulnerability | |
| Modificada | Alta (7.5) | 1.1% | — | Omniosce Omnios | 29/11/2019 | 17/6/2026 | illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences. | |
| Modificada | Alta (7.5) | 1.8% | — | Netreo Omnicenter | 9/10/2019 | 17/6/2026 | Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read sensitive information from the database used by the application. | |
| Modificada | Crítica (9.8) | 3.1% | — | Gitlab Omnibus | 16/9/2019 | 17/6/2026 | An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation | |
| Modificada | Alta (7.5) | 1.9% | — | Newgensoft Omniflow Intelligent Business Process Suite | 21/8/2019 | 17/6/2026 | Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side and fetched from the server every time the user visits the D, creating business confusion. In the… | |
| Modificada | Alta (7.8) | 0.37% | — | Intel Omni-path Fabric Manager GUI | 13/6/2019 | 17/6/2026 | Improper permissions in the installer for Intel(R) Omni-Path Fabric Manager GUI before version 10.9.2.1.1 may allow an authenticated user to potentially enable escalation of privilege via local attack. | |
| Modificada | Alta (8.8) | 1.5% | — | Omniauth | 26/4/2019 | 17/6/2026 | The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web… | |
| Modificada | Crítica (9.8) | 2.4% | — | Omniauth Saml | 17/4/2019 | 17/6/2026 | OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service… | |
| Modificada | Alta (8.1) | 0.91% | — | Omninova Vobot Firmware | 9/2/2018 | 17/6/2026 | VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information, and consequently execute arbitrary code, via a crafted certificate, as demonstrated by leveraging a hardcoded --no-check-certificate Wget… |