Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)6.3%—HP Release Control30/5/201617/6/2026
The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
ModificadaAlta (7.8)3.4%—Cisco Headend System Release6/7/201517/6/2026
Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91854.
ModificadaAlta (7.8)3.4%—Cisco Headend System Release30/6/201517/6/2026
Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91838.
ModificadaMedia (4.3)1.8%—Cisco Videoscape ConductorCisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408.
ModificadaMedia (5)1.9%—Cisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, via a crafted header in an HTTP request, aka Bug ID CSCus44909.
ModificadaAlta (7.8)3.4%—Cisco DTA Control SystemCisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco DTA Control System (DTACS) 4.0.0.9 and Cisco Headend System Release allow remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCus50642, CSCus50662, CSCus50625, CSCus50657, and CSCus68315.
ModificadaMedia (5)2.0%—Cisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco Headend System Release allows remote attackers to cause a denial of service (DHCP and TFTP outage) via a flood of crafted UDP traffic, aka Bug ID CSCus04097.
ModificadaMedia (6.5)1.6%—Broadcom Release Automation16/12/201417/6/2026
SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote authenticated users to execute arbitrary SQL commands via a crafted query.
ModificadaMedia (4.3)1.8%—Broadcom Release Automation16/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.92%—Broadcom Release Automation16/12/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (9)3.6%—HP Release Control28/6/201417/6/2026
Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to gain privileges via unknown vectors.
ModificadaMedia (4)6.8%💥 ExploitHP Release Control28/6/201417/6/2026
Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors.
ModificadaAlta (9)6.8%—Xangati Software ReleaseXangati XNR15/4/201417/6/2026
Xangati XSR before 11 and XNR before 7 allows remote attackers to execute arbitrary commands via shell metacharacters in a gui_input_test.pl params parameter to servlet/Installer.
ModificadaAlta (7.8)5.9%💥 ExploitXangati Software ReleaseXangati XNR15/4/201417/6/2026
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatus action to servlet/MGConfigData, (2) the download parameter in a download action to servlet/MGConfigData, (3) the…
ModificadaMedia (6.2)0.44%—Fedora Project Fedora Release RawhideRedhat Enterprise Linux22/2/201316/6/2026
A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use…
ModificadaAlta (7.5)2.3%💥 ExploitV-eva Press Release Script23/11/201116/6/2026
SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)1.5%—DokeosDokeos Community Release10/5/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allow remote attackers to execute arbitrary PHP code via a URL in the (1) rootSys and (2) clarolineRepositorySys parameters, and possibly the (3) lang_path, (4)…
ModificadaAlta (10)3.8%—Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+820/4/200616/6/2026
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
Orbitaley — Vulnerabilidades