Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1785 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.40% | — | Dell Insightiq | 10/9/2024 | 17/6/2026 | Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to read, modify, and delete arbitrary files. | |
| Analizada | Media (6.7) | 0.15% | — | Dell Insightiq | 10/9/2024 | 17/6/2026 | Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (4.4) | 0.14% | — | Dell Insightiq | 10/9/2024 | 17/6/2026 | Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Baja (3.1) | 0.18% | — | Rapid7 Insight Platform | 9/9/2024 | 17/6/2026 | Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being added to the incorrect customer. This… | |
| Analizada | Media (4.3) | 0.57% | — | Vmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Oncommand Insight | 20/8/2024 | 17/6/2026 | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: | |
| Analizada | Media (5) | 0.26% | — | SAP CRM Abap Insights Management | 13/8/2024 | 17/6/2026 | SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application. | |
| Analizada | Crítica (9.8) | 0.27% | — | Opentext Arcsight Intelligence | 6/8/2024 | 17/6/2026 | Privilege escalation vulnerability identified in OpenText ArcSight Intelligence. | |
| Analizada | Alta (8.8) | 0.28% | — | Opentext Arcsight Intelligence | 6/8/2024 | 17/6/2026 | Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence. | |
| Analizada | Alta (8.8) | 0.28% | — | Opentext Arcsight Intelligence | 6/8/2024 | 17/6/2026 | Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence. | |
| Analizada | Alta (7.5) | 0.28% | — | Dell Insightiq | 1/8/2024 | 17/6/2026 | Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Media (5.3) | 0.32% | — | Rapid7 Insightvm | 18/7/2024 | 17/6/2026 | Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it to overload or crash by sending repeated invalid REST requests in a short timeframe, to the Console's port 443 causing the console to enter an… | |
| Analizada | Alta (7.4) | 1.1% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+6 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Modificada | Media (4.8) | 0.86% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+4 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Media (4.8) | 0.94% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+6 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Baja (3.7) | 1.3% | — | Netapp Active IQ Unified ManagerNetapp BluexpNetapp Data Infrastructure Insights Storage Workload Security AgentNetapp Oncommand Insight+5 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Analizada | Baja (3.7) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+5 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Modificada | Media (6.1) | 0.40% | — | Monsterinsights Userfeedback | 12/7/2024 | 17/6/2026 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.4) | 0.35% | — | Opentext Arcsight LoggerAI | 11/6/2024 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited. | |
| Analizada | Media (4.9) | 0.41% | — | Beyondtrust Beyondinsight Password Safe | 11/6/2024 | 17/6/2026 | A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response. | |
| Analizada | Baja (2.7) | 0.27% | — | Beyondtrust Beyondinsight Password Safe | 11/6/2024 | 17/6/2026 | A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request. | |
| Modificada | Media (5.3) | 0.26% | — | Beyondtrust Beyondinsight | 4/6/2024 | 17/6/2026 | Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames. | |
| Modificada | Crítica (9.1) | 0.22% | — | Beyondtrust Beyondinsight | 4/6/2024 | 17/6/2026 | Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability. | |
| Analizada | Media (6.1) | 0.27% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Analizada | Alta (7.4) | 0.35% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic | |
| Analizada | Alta (7.5) | 0.42% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service |