Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1785 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.40%—Dell Insightiq10/9/202417/6/2026
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to read, modify, and delete arbitrary files.
AnalizadaMedia (6.7)0.15%—Dell Insightiq10/9/202417/6/2026
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaMedia (4.4)0.14%—Dell Insightiq10/9/202417/6/2026
Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
AnalizadaBaja (3.1)0.18%—Rapid7 Insight Platform9/9/202417/6/2026
Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being added to the incorrect customer. This…
AnalizadaMedia (4.3)0.57%—Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Oncommand Insight20/8/202417/6/2026
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true:
AnalizadaMedia (5)0.26%—SAP CRM Abap Insights Management13/8/202417/6/2026
SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
AnalizadaCrítica (9.8)0.27%—Opentext Arcsight Intelligence6/8/202417/6/2026
Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.
AnalizadaAlta (8.8)0.28%—Opentext Arcsight Intelligence6/8/202417/6/2026
Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.
AnalizadaAlta (8.8)0.28%—Opentext Arcsight Intelligence6/8/202417/6/2026
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
AnalizadaAlta (7.5)0.28%—Dell Insightiq1/8/202417/6/2026
Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure.
ModificadaMedia (5.3)0.32%—Rapid7 Insightvm18/7/202417/6/2026
Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it to overload or crash by sending repeated invalid REST requests in a short timeframe, to the Console's port 443 causing the console to enter an…
AnalizadaAlta (7.4)1.1%—Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+616/7/202417/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM…
ModificadaMedia (4.8)0.86%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+416/7/202417/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM…
AnalizadaMedia (4.8)0.94%—Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+616/7/202417/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM…
AnalizadaBaja (3.7)1.3%—Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+516/7/202417/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM…
AnalizadaBaja (3.7)1.0%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+516/7/202417/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM…
ModificadaMedia (6.1)0.40%—Monsterinsights Userfeedback12/7/202417/6/2026
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (8.4)0.35%—Opentext Arcsight LoggerAI11/6/202417/6/2026
Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.
AnalizadaMedia (4.9)0.41%—Beyondtrust Beyondinsight Password Safe11/6/202417/6/2026
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
AnalizadaBaja (2.7)0.27%—Beyondtrust Beyondinsight Password Safe11/6/202417/6/2026
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
ModificadaMedia (5.3)0.26%—Beyondtrust Beyondinsight4/6/202417/6/2026
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
ModificadaCrítica (9.1)0.22%—Beyondtrust Beyondinsight4/6/202417/6/2026
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.
AnalizadaMedia (6.1)0.27%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
AnalizadaAlta (7.4)0.35%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
AnalizadaAlta (7.5)0.42%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service