Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)1.5%—Openstack Nova26/11/201916/6/2026
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker…
ModificadaMedia (5.5)0.29%—Cubot Nova Firmware14/11/201917/6/2026
The Cubot Nova Android device with a build fingerprint of CUBOT/CUBOT_NOVA/CUBOT_NOVA:8.1.0/O11019/1527060122:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property…
AnalizadaAlta (7.8)72%⚠ Explotación activa💥 ExploitGoogle AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+7311/10/201917/6/2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing…
ModificadaAlta (8.1)2.7%💥 PoCGoogle AndroidApple Iphone OSApple MAC OS XApple Tvos+14314/8/201917/6/2026
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the…
ModificadaMedia (6.5)1.9%—Openstack NovaCanonical Ubuntu LinuxRedhat OpenstackDebian Linux9/8/201917/6/2026
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or…
ModificadaAlta (8.8)1.0%—Python Novajoin30/7/201917/6/2026
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
ModificadaMedia (6.1)1.2%—Novaksolutions Infusionsoft-php-sdk3/7/201917/6/2026
novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution
ModificadaAlta (8.6)0.74%—Openstack Nova22/4/201916/6/2026
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
ModificadaAlta (8.8)0.75%—Hetronic Nova-m FirmwareHetronic Es-can-hl FirmwareHetronic Bms-hl FirmwareHetronic MLC Firmware+125/1/201917/6/2026
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.
ModificadaMedia (5.3)0.76%—Huawei VIP APPHuawei Mate 20 FirmwareHuawei Nova 3I FirmwareHuawei Nova 3 Firmware4/12/201817/6/2026
Huawei VIP App is a mobile app for Malaysia customers that purchased P20 Series, Nova 3/3i and Mate 20. There is a vulnerability in versions before 4.0.5 that attackers can conduct bruteforce to the VIP App Web Services to get user information.
ModificadaMedia (4.6)0.22%—Huawei Nova 2 Plus FirmwareHuawei Mate 9 PRO Firmware27/11/201817/6/2026
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker uses a data cable to connect the smartphone to another smartphone and then perform a series of specific operations. Successful exploit could allow the attacker…
ModificadaMedia (6.4)0.57%—Inova-software Inova Partner16/11/201817/6/2026
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference.
ModificadaMedia (6.4)0.53%—Inova-software Inova Partner16/11/201817/6/2026
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions.
ModificadaAlta (7.5)1.1%—Anovabace Project Anovabace9/7/201817/6/2026
The mintToken function of a smart contract implementation for AnovaBace, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)3.7%—Openstack NovaRedhat Openstack19/2/201817/6/2026
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data…
ModificadaAlta (8.1)0.91%—Omninova Vobot Firmware9/2/201817/6/2026
VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information, and consequently execute arbitrary code, via a crafted certificate, as demonstrated by leveraging a hardcoded --no-check-certificate Wget…
ModificadaAlta (7.5)3.1%—Omninova Vobot Firmware9/2/201817/6/2026
An issue was discovered on VOBOT CLOCK before 0.99.30 devices. Cleartext HTTP is used to download a breakout program, and therefore man-in-the-middle attackers can execute arbitrary code by watching for a local user to launch the Breakout Easter Egg feature, and then sending a crafted HTTP response.
ModificadaCrítica (9.8)1.6%—Omninova Vobot Firmware9/2/201817/6/2026
An issue was discovered on VOBOT CLOCK before 0.99.30 devices. An SSH server exists with a hardcoded vobot account that has root access.
ModificadaAlta (7.5)1.2%—Lenova Flex System X240 M5 FirmwareLenova Flex System X280 X6 FirmwareLenova Flex System X440 M4 FirmwareLenova Flex System X480 X6 Firmware+3826/1/201817/6/2026
An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Flooding the IMM2 with a high volume of authentication failures via the Common Information Model (CIM) used by LXCA and OneCLI…
ModificadaAlta (8.6)2.0%—Openstack Nova5/12/201717/6/2026
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled resource allocations. This regression was introduced with the fix…
ModificadaMedia (6.2)0.28%—Huawei Honor 8 FirmwareHuawei Honor V8 FirmwareHuawei Honor 9 FirmwareHuawei Honor V9 Firmware+522/11/201717/6/2026
Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL20C00B391, versions earlier than KNT-UL10C00B391, versions…
ModificadaMedia (6.2)0.27%—Huawei Honor 8 FirmwareHuawei Honor V8 FirmwareHuawei Honor 9 FirmwareHuawei Honor V9 Firmware+522/11/201717/6/2026
Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL20C00B391, versions earlier than KNT-UL10C00B391, versions…
ModificadaAlta (7.8)1.0%—Huawei Nova 2 FirmwareHuawei Nova 2 Plus Firmware22/11/201717/6/2026
The Bastet Driver of Nova 2 Plus,Nova 2 Huawei smart phones with software of Versions earlier than BAC-AL00C00B173,Versions earlier than PIC-AL00C00B173 has a use after free (UAF) vulnerability. An attacker can convince a user to install a malicious application which has a high privilege to exploit this vulnerability,…
ModificadaMedia (6.5)1.4%—Openstack Nova14/11/201717/6/2026
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All setups using Nova Filter Scheduler are…
ModificadaCrítica (9.8)5.6%—Novastor Novabackup Datacenter13/4/201717/6/2026
The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.
Orbitaley — Vulnerabilidades