Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.9% | — | Dell EMC Data Protection Advisor | 6/7/2020 | 17/6/2026 | Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on the affected system. | |
| Modificada | Crítica (9.8) | 1.4% | — | Broadcom Brocade Network Advisor | 29/6/2020 | 17/6/2026 | A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. | |
| Modificada | Media (4.3) | 0.68% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 6/5/2020 | 17/6/2026 | A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system. The vulnerability is due to incorrect… | |
| Modificada | Alta (7.2) | 4.6% | — | Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance Firmware | 18/3/2020 | 17/6/2026 | Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject… | |
| Modificada | Alta (7.2) | 3.9% | — | Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance Firmware | 18/3/2020 | 17/6/2026 | Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter… | |
| Modificada | Media (5.9) | 1.8% | — | Apache CXFApache Wss4jRedhat Jboss Business Rules Management SystemRedhat Jboss Enterprise Application Platform+6 | 11/3/2020 | 16/6/2026 | The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat Enterprise VirtualizationRedhat Enterprise Virtualization Hypervisor | 25/2/2020 | 17/6/2026 | VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to… | |
| Modificada | Media (5.3) | 1.4% | — | IBM Qradar Advisor | 25/2/2020 | 17/6/2026 | IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 171438. | |
| Modificada | Alta (7.5) | 0.79% | — | IBM Qradar Advisor | 25/2/2020 | 17/6/2026 | IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206. | |
| Modificada | Media (6.1) | 1.2% | — | Mcafee WEB Advisor | 24/2/2020 | 17/6/2026 | Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote unauthenticated attacker to execute arbitrary code via a cross site scripting attack. | |
| Modificada | Media (6.5) | 0.84% | — | Hitachi Device ManagerHitachi Compute Systems ManagerHitachi Automation DirectorHitachi Tiered Storage Manager+4 | 14/2/2020 | 17/6/2026 | A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device… | |
| Modificada | Alta (7.5) | 3.6% | — | NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+2 | 27/1/2020 | 17/6/2026 | Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869. | |
| Modificada | Media (4.3) | 0.82% | — | Jenkins Health Advisor BY Cloudbees | 15/1/2020 | 17/6/2026 | A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient. | |
| Modificada | Alta (8.8) | 0.84% | — | Jenkins Health Advisor BY Cloudbees | 15/1/2020 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient. | |
| Modificada | Media (6.5) | 1.5% | — | Mcafee Webadvisor | 3/12/2019 | 17/6/2026 | API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restricted websites via a carefully crafted web site. | |
| Modificada | Media (6.5) | 0.94% | — | Mcafee Webadvisor | 3/12/2019 | 17/6/2026 | Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully crafted web site. | |
| Modificada | Alta (8.8) | 1.7% | — | Omron Cx-supervisorTeamviewer | 26/11/2019 | 17/6/2026 | In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit. | |
| Modificada | Alta (7.5) | 1.9% | — | Python PyxmlRedhat Enterprise Virtualization HypervisorRedhat Enterprise Linux | 22/11/2019 | 16/6/2026 | PyXML: Hash table collisions CPU usage Denial of Service | |
| Modificada | Alta (7.5) | 1.3% | — | Hitachi Device ManagerHitachi Replication ManagerHitachi Tiered Storage ManagerHitachi Infrastructure Analytics Advisor+1 | 12/11/2019 | 17/6/2026 | A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.7.0-00 allows an unauthenticated remote user to trigger a denial of service (DoS) condition because of Uncontrolled Resource Consumption. | |
| Modificada | Media (6.5) | 0.76% | — | IBM Qradar Advisor With Watson | 9/11/2019 | 17/6/2026 | IBM QRadar Advisor 1.0.0 through 2.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 166205. | |
| Modificada | Alta (8.2) | 2.3% | — | Supervisord Supervisor | 10/9/2019 | 17/6/2026 | In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the… | |
| Modificada | Crítica (9.8) | 4.5% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is… | |
| Modificada | Crítica (9.8) | 76% | 💥 Exploit | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user… | |
| Modificada | Alta (7.2) | 39% | 💥 Exploit | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of… | |
| Modificada | Crítica (9.8) | 83% | 💥 Exploit | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The… |