Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.36% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This vulnerability is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this… | |
| Analizada | Media (6.5) | 0.49% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this… | |
| Analizada | Media (5.4) | 0.36% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending… | |
| Analizada | Alta (8.8) | 1.1% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user authorization and insufficient validation of… | |
| Analizada | Media (5.9) | 0.30% | — | Cisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered.… | |
| Modificada | Crítica (9.4) | 19% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/7/2024 | 17/6/2026 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely | |
| Modificada | Crítica (9.4) | 17% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/7/2024 | 17/6/2026 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized | |
| Analizada | Alta (8.7) | 1.5% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+9 | 1/7/2024 | 17/6/2026 | Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. | |
| Aplazada | Alta (7.5) | 18% | 💥 Exploit | Sonatype Nexus RepositoryAI | 16/5/2024 | 17/6/2026 | Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1. | |
| Analizada | Alta (7.5) | 0.80% | — | Cisco Nexus Dashboard Fabric Controller | 3/4/2024 | 17/6/2026 | A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through… | |
| Analizada | Media (4.3) | 0.38% | — | Cisco Nexus Dashboard Orchestrator | 3/4/2024 | 17/6/2026 | A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user… | |
| Analizada | Media (4.3) | 0.41% | — | Cisco Nexus Dashboard | 3/4/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by sending queries to the API endpoint. A… | |
| Analizada | Media (6) | 0.17% | — | Cisco Nexus Dashboard | 3/4/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this… | |
| Analizada | Alta (8.8) | 0.26% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the… | |
| Aplazada | Media (5.6) | 0.17% | — | Hitachi Cosminexus Component ContainerAI | 12/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 11-20 before 11-20-07, from 11-10 before 11-10-10, from 11-00 before 11-00-12,… | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Nexus Platform | 13/12/2023 | 17/6/2026 | Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Nexus Platform | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 0.44% | — | Jenkins Nexus Platform | 13/12/2023 | 17/6/2026 | Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Nexus Platform | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML. | |
| Modificada | Media (6.5) | 0.67% | — | Jenkins Maven Artifact Choicelistprovider (nexus) | 16/8/2023 | 17/6/2026 | Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. | |
| Modificada | Alta (7.2) | 0.96% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user. | |
| Modificada | Media (5.4) | 0.55% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user. | |
| Modificada | Alta (7.8) | 0.18% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`' | |
| Modificada | Alta (7.2) | 1.2% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC… | |
| Modificada | Alta (7.4) | 0.69% | — | Osnexus Quantastor | 10/7/2023 | 17/6/2026 | An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDRESS>:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror=alert(document.cookie)> |