Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 7.8% | — | Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+20 | 21/1/2020 | 17/6/2026 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. | |
| Modificada | Alta (7.5) | 3.1% | — | Xmlsoft Libxml2Debian LinuxNetapp Cloud BackupNetapp Clustered Data Ontap+20 | 21/1/2020 | 17/6/2026 | xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. | |
| Modificada | Alta (8.2) | 2.6% | — | Agendaless WaitressOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian LinuxFedoraproject Fedora+1 | 26/12/2019 | 17/6/2026 | In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests containing special whitespace characters in… | |
| Modificada | Alta (7.5) | 2.4% | — | Agendaless WaitressOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian LinuxFedoraproject Fedora+1 | 20/12/2019 | 17/6/2026 | Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separated list, with the inner-most encoding… | |
| Modificada | Alta (7.5) | 2.5% | — | Agendaless WaitressOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian LinuxFedoraproject Fedora+1 | 20/12/2019 | 17/6/2026 | Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any preceding CR." Unfortunately if a front-end server does not parse… | |
| Modificada | Media (4.4) | 0.31% | — | IBM Spectrum ProtectIBM Spectrum Protect FOR Virtual Environments | 25/11/2019 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551. | |
| Modificada | Crítica (9.8) | 1.7% | — | Vanderbilt Adaptive Communication EnvironmentDebian Linux | 22/11/2019 | 17/6/2026 | generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (8.8) | 0.66% | — | IBM Maximo FOR OIL AND GASIBM Maximo Health, Safety AND Environment Manager | 29/10/2019 | 17/6/2026 | After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allowed to access. IBM X-Force ID: 165948. | |
| Modificada | Media (5.4) | 0.69% | — | Jenkins Build Environment | 12/9/2019 | 17/6/2026 | Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties. | |
| Modificada | Media (6.1) | 1.1% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating EnvironmentDell EMC Vnxe3200 Firmware | 3/9/2019 | 17/6/2026 | Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this… | |
| Modificada | Crítica (9.8) | 3.5% | — | Mixin-deep Project Mixin-deepFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment | 23/8/2019 | 17/6/2026 | mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. | |
| Modificada | Alta (7.8) | 0.34% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment | 18/7/2019 | 17/6/2026 | Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user’s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the… | |
| Modificada | Media (4.3) | 1.1% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment | 18/7/2019 | 17/6/2026 | Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Server quotas configuration. A remote authenticated Unisphere Operator could potentially exploit this vulnerability to edit quota configuration of other users. | |
| Modificada | Media (4.7) | 0.22% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 8/4/2019 | 17/6/2026 | In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968. | |
| Modificada | Media (5.5) | 0.30% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments | 8/4/2019 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872. | |
| Modificada | Alta (7.5) | 2.4% | — | IBM Spectrum ProtectIBM Tivoli Storage ManagerIBM Spectrum Protect Manager FOR Virtual Environments Data Protection FOR VmwareIBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR Vmware+2 | 12/11/2018 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871. | |
| Modificada | Alta (7.8) | 2.3% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxSystemd Project SystemdOracle Communications Cloud Native Core Network Function Cloud Native Environment | 26/10/2018 | 17/6/2026 | A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239. | |
| Modificada | Alta (7.8) | 0.39% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment | 5/10/2018 | 17/6/2026 | Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability to alter multiple library files in service tools that might result in arbitrary code… | |
| Modificada | Media (6.1) | 1.1% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment | 28/9/2018 | 17/6/2026 | Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by… | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Virtual Environments | 26/9/2018 | 17/6/2026 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870. | |
| Modificada | Media (5.5) | 0.29% | — | IBM Tivoli Storage ManagerIBM Tivoli Storage Manager FOR Space ManagementIBM Tivoli Storage Manager FOR Virtual Environments | 26/9/2018 | 17/6/2026 | IBM Spectrum Protect 7.1 and 8.1 could allow a local user to corrupt or delete highly sensitive information that would cause a denial of service to other users. IBM X-Force ID: 142696. | |
| Modificada | Alta (7.5) | 0.97% | — | IBM Spectrum Protect ClientIBM Spectrum Protect FOR Virtual Environments | 26/9/2018 | 17/6/2026 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 142649. | |
| Modificada | Alta (7.2) | 3.3% | — | Dell EMC Unity Operating EnvironmentDell EMC Unityvsa Operating Environment | 8/5/2018 | 17/6/2026 | Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could potentially exploit the vulnerabilities to execute arbitrary OS commands as system root on the system where Dell EMC Unity is installed. | |
| Modificada | Crítica (9.8) | 2.0% | — | Dell EMC SmisDell EMC Solutions Enabler Virtual ApplianceDell EMC UnisphereDell EMC Unity Operating Environment+12 | 30/4/2018 | 17/6/2026 | In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions… |