Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.7% | — | Git-interface Project Git-interface | 22/4/2022 | 17/6/2026 | Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be… | |
| Modificada | Media (6.1) | 0.68% | — | Compassplus Tranzware OnlineCompassplus Tranzware Online Financial Institution Maintenance Interface | 14/2/2022 | 17/6/2026 | A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to… | |
| Modificada | Crítica (9.8) | 1.3% | — | Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+42 | 11/2/2022 | 17/6/2026 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition. | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Media (5.3) | 0.44% | — | Sysaid Application Programming Interface | 14/12/2021 | 17/6/2026 | Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 PoC | Npmjs NPMNetapp Next Generation Application Programming InterfaceFedoraproject Fedora | 13/11/2021 | 17/6/2026 | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact… | |
| Modificada | Media (5.4) | 0.90% | — | Pi-hole WEB Interface | 26/10/2021 | 17/6/2026 | Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was patched in version 5.8. | |
| Modificada | Alta (7.5) | 12% | — | Apache TomcatNetapp HCINetapp Management Services FOR Element SoftwareDebian Linux+14 | 14/10/2021 | 17/6/2026 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a… | |
| Modificada | Alta (7.5) | 1.7% | — | Docker Command Line InterfaceFedoraproject Fedora | 4/10/2021 | 17/6/2026 | Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically `~/.docker/config.json`) listing a `credsStore` or `credHelpers` that could not be executed would… | |
| Modificada | Media (6.1) | 0.55% | — | Pi-hole WEB Interface | 17/9/2021 | 17/6/2026 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.1) | 0.55% | — | Pi-hole WEB Interface | 17/9/2021 | 17/6/2026 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (7.5) | 1.1% | — | Pi-hole WEB Interface | 15/9/2021 | 17/6/2026 | adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag | |
| Modificada | Media (5.4) | 0.64% | — | IBM Sterling Connect Direct User Interface | 26/7/2021 | 17/6/2026 | IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further… | |
| Modificada | Alta (8.8) | 0.67% | — | Pi-hole FtldnsPi-holePi-hole WEB Interface | 15/4/2021 | 17/6/2026 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details. | |
| Modificada | Alta (7.2) | 1.5% | — | Linuxfoundation Container Network Interface | 26/3/2021 | 17/6/2026 | An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an… | |
| Modificada | Crítica (9.8) | 6.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all… | |
| Modificada | Crítica (9.8) | 3.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3… | |
| Modificada | Alta (7.8) | 1.3% | — | Emerson Rosemount Transmitter Interface SoftwarePepperl-fuchs PactwareWago Dtminspector 3Wago Fdtcontainer Application+3 | 22/1/2021 | 17/6/2026 | M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. | |
| Modificada | Media (6.5) | 2.3% | — | Kubernetes Container Storage Interface Snapshotter | 21/1/2021 | 17/6/2026 | Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically… | |
| Modificada | Media (6.5) | 0.29% | — | SAP Graphical User Interface | 12/1/2021 | 17/6/2026 | SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend systems in the client PCs memory. Under certain conditions the attacker can access information which would otherwise be restricted. The exploit can only be executed locally on the client PC and not… | |
| Modificada | Crítica (9.8) | 2.0% | — | Corenlp-js-interface Project Corenlp-js-interface | 11/12/2020 | 17/6/2026 | All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function. | |
| Modificada | Alta (7.5) | 5.3% | — | CodemirrorOracle Application ExpressOracle Enterprise Manager Express User InterfaceOracle Essbase+2 | 30/10/2020 | 17/6/2026 | This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the… | |
| Modificada | Crítica (9.8) | 0.87% | — | 1password Command Line Interface1password Scim | 27/10/2020 | 17/6/2026 | An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force… | |
| Modificada | Alta (7.1) | 0.61% | — | Perl Database InterfaceOpensuse LeapDebian LinuxFedoraproject Fedora | 16/9/2020 | 17/6/2026 | A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data. | |
| Modificada | Media (5.5) | 0.58% | — | Perl Database InterfaceCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora+1 | 16/9/2020 | 17/6/2026 | An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability. |