Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
482 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.97% | — | Jenkins Ns-nd Integration Performance Publisher | 21/9/2022 | 17/6/2026 | A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials. | |
| Modificada | Alta (8.8) | 0.54% | — | Jenkins Ns-nd Integration Performance Publisher | 21/9/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials. | |
| Modificada | Alta (7.8) | 0.75% | — | GNU GlibcDebian LinuxNetapp E-series Performance AnalyzerNetapp NFS Plug-in+6 | 24/8/2022 | 17/6/2026 | A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and… | |
| Modificada | Media (6.5) | 0.77% | — | Jenkins Clif Performance Testing | 27/7/2022 | 17/6/2026 | An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows attackers with Overall/Read permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content. | |
| Modificada | Alta (7.5) | 2.9% | — | GrafanaNetapp E-series Performance Analyzer | 15/7/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that… | |
| Modificada | Alta (8.7) | 70% | — | GrafanaNetapp E-series Performance Analyzer | 15/7/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to… | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Ns-nd Integration Performance Publisher | 23/6/2022 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.8) | 0.83% | — | IBM Sevone Network Performance Management | 7/6/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remotely. | |
| Modificada | Alta (8.8) | 0.82% | — | IBM Sevone Network Performance Management | 7/6/2022 | 17/6/2026 | A vulnerability classified as critical was found in SevOne Network Management System up to 5.7.2.22. This vulnerability affects the Alert Summary. The manipulation leads to sql injection. The attack can be initiated remotely. | |
| Modificada | Alta (8.8) | 4.1% | — | IBM Sevone Network Performance Management | 7/6/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manipulation leads to privilege escalation with a command injection. It is possible to initiate the attack remotely. | |
| Modificada | Alta (7.8) | 0.58% | — | Samba Cifs-utilsDebian LinuxSuse Caas PlatformSuse Enterprise Storage+15 | 27/4/2022 | 17/6/2026 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. | |
| Modificada | Media (6.1) | 3.2% | — | Solarwinds Database Performance AnalyzerSolarwinds Database Performance Monitor | 21/4/2022 | 17/6/2026 | Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query | |
| Modificada | Crítica (9.8) | 1.3% | — | Employee Performance Evaluation Project Employee Performance Evaluation | 5/4/2022 | 17/6/2026 | Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter. | |
| Modificada | Media (5.5) | 0.24% | — | Intel Integrated Performance Primitives Cryptography | 9/2/2022 | 17/6/2026 | Improper conditions check in the Intel(R) IPP Crypto library before version 2021.2 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.24% | — | Intel Graphics Performance Analyzers | 9/2/2022 | 17/6/2026 | Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.3) | 1.2% | — | GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora | 8/2/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will… | |
| Modificada | Alta (8.8) | 2.3% | — | GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora | 8/2/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An… | |
| Modificada | Media (5.4) | 2.3% | — | GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora | 8/2/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either… | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa💥 Exploit | Polkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+26 | 28/1/2022 | 15/8/2026 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Alta (7.5) | 50% | 💥 PoC | OpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+12 | 14/12/2021 | 17/6/2026 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as… | |
| Modificada | Media (5.5) | 0.22% | — | Intel NUC M15 Laptop KIT Lapbc510 FirmwareIntel NUC M15 Laptop KIT Lapbc710 FirmwareIntel NUC 11 Compute Element Cm11ebc4w FirmwareIntel NUC 11 Compute Element Cm11ebi38w Firmware+99 | 17/11/2021 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (4.3) | 0.45% | — | WP Performance Score Booster Project WP Performance Score Booster | 17/11/2021 | 17/6/2026 | The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Modificada | Media (6.5) | 1.7% | — | Jenkins Performance | 12/11/2021 | 17/6/2026 | Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (4.7) | 0.58% | — | Solarwinds Database Performance Analyzer | 21/10/2021 | 17/6/2026 | This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim. |