Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.36%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This vulnerability is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this…
AnalizadaMedia (6.5)0.49%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this…
AnalizadaMedia (5.4)0.36%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending…
AnalizadaAlta (8.8)1.1%—Cisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device.   This vulnerability is due to improper user authorization and insufficient validation of…
AnalizadaMedia (5.9)0.30%—Cisco Nexus Dashboard Orchestrator2/10/202417/6/2026
This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered.…
ModificadaCrítica (9.4)19%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/7/202417/6/2026
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
ModificadaCrítica (9.4)17%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/7/202417/6/2026
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized
AnalizadaAlta (8.7)1.5%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+91/7/202417/6/2026
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
AplazadaAlta (7.5)18%💥 ExploitSonatype Nexus RepositoryAI16/5/202417/6/2026
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.
AnalizadaAlta (7.5)0.80%—Cisco Nexus Dashboard Fabric Controller3/4/202417/6/2026
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through…
AnalizadaMedia (4.3)0.38%—Cisco Nexus Dashboard Orchestrator3/4/202417/6/2026
A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user…
AnalizadaMedia (4.3)0.41%—Cisco Nexus Dashboard3/4/202417/6/2026
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by sending queries to the API endpoint. A…
AnalizadaMedia (6)0.17%—Cisco Nexus Dashboard3/4/202417/6/2026
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this…
AnalizadaAlta (8.8)0.26%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator3/4/202417/6/2026
A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the…
AplazadaMedia (5.6)0.17%—Hitachi Cosminexus Component ContainerAI12/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 11-20 before 11-20-07, from 11-10 before 11-10-10, from 11-00 before 11-00-12,…
ModificadaMedia (4.3)0.48%—Jenkins Nexus Platform13/12/202317/6/2026
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaAlta (8.8)0.45%—Jenkins Nexus Platform13/12/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaMedia (5.4)0.44%—Jenkins Nexus Platform13/12/202317/6/2026
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.
ModificadaAlta (8.8)0.45%—Jenkins Nexus Platform13/12/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.
ModificadaMedia (6.5)0.67%—Jenkins Maven Artifact Choicelistprovider (nexus)16/8/202317/6/2026
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
ModificadaAlta (7.2)0.96%—Osnexus Quantastor10/7/202317/6/2026
An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user.
ModificadaMedia (5.4)0.55%—Osnexus Quantastor10/7/202317/6/2026
An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) “id | tee /tmp/ttttttddddssss” as root. /tmp/ttttttddddssss it'll contain the ids of the root user.
ModificadaAlta (7.8)0.18%—Osnexus Quantastor10/7/202317/6/2026
Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgrade.py?taskId=1&a=;`whoami`'
ModificadaAlta (7.2)1.2%—Osnexus Quantastor10/7/202317/6/2026
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC…
ModificadaAlta (7.4)0.69%—Osnexus Quantastor10/7/202317/6/2026
An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDRESS>:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror=alert(document.cookie)>