Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

8534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisMedia (6.8)0.28%—Nvidia UFM EnterpriseAI25/8/202628/8/2026
NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure.
En análisisMedia (5.1)0.13%—Nvidia UFM EnterpriseAI25/8/202628/8/2026
NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges.
Pendiente de análisisAlta (7.7)0.20%—Tuleap Enterprise EditionAI25/8/202628/8/2026
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.
AnalizadaMedia (6.1)0.26%—GimpRedhat Enterprise Linux24/8/20261/9/2026
A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service…
AplazadaAlta (8.3)0.22%—ARC EnterpriseAI21/8/20269/9/2026
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode) of inbound messages. The `MsgReplicateSync` payload itself is accepted without…
AnalizadaMedia (6.5)0.43%—Redhat Enterprise LinuxFreeipa20/8/202624/8/2026
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service,…
ModificadaAlta (7.5)0.43%—Redhat Enterprise LinuxFreeipa20/8/202628/9/2026
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS)…
ModificadaAlta (7.5)0.43%—Redhat Enterprise LinuxFreeipa20/8/202628/9/2026
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage,…
ModificadaAlta (8.7)0.43%—Redhat Enterprise LinuxFreeipa20/8/202628/9/2026
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service…
ModificadaAlta (8.1)0.22%—FreeipaRedhat Enterprise Linux20/8/202628/9/2026
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS)…
AnalizadaMedia (5.3)0.39%—Cisco Talos Intelligence FOR Enterprise Security Cloud19/8/202621/8/2026
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and…
AnalizadaAlta (8.8)0.42%—Cisco Talos Intelligence FOR Enterprise Security Cloud19/8/202621/8/2026
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to…
AnalizadaAlta (8.1)0.35%—Splunk Enterprise Security19/8/202625/8/2026
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all relevant data and system integrity through…
AnalizadaAlta (8.1)0.40%—Splunk Enterprise Security19/8/202625/8/2026
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the…
Pendiente de análisisMedia (5)0.44%—Cisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAI19/8/202620/8/2026
A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
AnalizadaAlta (8.8)0.44%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaMedia (5.4)0.23%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaMedia (6.5)0.45%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaMedia (6.5)0.38%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaAlta (8.8)0.44%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
AnalizadaAlta (7.2)0.46%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (8.8)0.44%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
AnalizadaAlta (7.2)2.0%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
AnalizadaAlta (8.8)2.3%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
AnalizadaAlta (7.2)0.27%—Dell Openmanage Enterprise19/8/202621/8/2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.