Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
411 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not… | |
| Analizada | Media (4.7) | 0.27% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+18 | 8/5/2024 | 17/6/2026 | When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.8) | 0.27% | — | IBM Storage Defender Resiliency Service | 12/4/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986. | |
| Modificada | Alta (7.2) | 2.3% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 2.3% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 3.2% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Remote Code Execution Vulnerability | |
| Analizada | Alta (7.2) | 2.3% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 3.2% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Remote Code Execution Vulnerability | |
| Analizada | Alta (7.2) | 3.1% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 0.73% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender… | |
| Analizada | Crítica (9.8) | 0.52% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089… | |
| Analizada | Alta (7.8) | 0.20% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 1/4/2024 | 17/6/2026 | A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total… | |
| Aplazada | Media (6.1) | 0.31% | — | Opswat Metadefender CoreAI | 27/3/2024 | 17/6/2026 | Opswat Metadefender Core before 5.2.1 does not properly defend against potential HTML injection and XSS attacks. | |
| Analizada | Media (5.5) | 0.91% | — | Microsoft Windows Defender Antimalware Platform | 12/3/2024 | 17/6/2026 | Microsoft Defender Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.8) | 0.64% | — | Microsoft Defender FOR Endpoint | 13/2/2024 | 10/8/2026 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.13% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 278749. | |
| Modificada | Media (5.5) | 0.15% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748. | |
| Modificada | Alta (7.2) | 0.42% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783. | |
| Modificada | Media (5.4) | 0.33% | — | IBM Storage Defender Data Protect | 19/1/2024 | 17/6/2026 | IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM… | |
| Modificada | Alta (7.5) | 0.48% | — | Wpmudev Defender Security | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security – Malware Scanner, Login Security & Firewall: from n/a through 4.1.0. | |
| Modificada | Alta (7.8) | 0.81% | — | Microsoft Windows Defender | 14/11/2023 | 17/6/2026 | Microsoft Windows Defender Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 4.5% | ⚠ Explotación activa | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Carrier-grade NATF5 Big-ip Ddos Hybrid Defender+16 | 26/10/2023 | 17/6/2026 | An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Carrier-grade NAT+16 | 26/10/2023 | 17/6/2026 | Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Media (5.3) | 2.2% | 💥 Exploit | Wpmudev Defender Security | 16/10/2023 | 17/6/2026 | The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled. |