Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.0% | — | GNU GlibcFedoraproject FedoraOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native Environment+4 | 12/8/2021 | 17/6/2026 | In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix. | |
| Modificada | Media (5.9) | 2.2% | — | Redhat XnioRedhat Jboss BrmsRedhat Jboss Data GridRedhat Jboss Data Virtualization+10 | 2/6/2021 | 17/6/2026 | A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final. | |
| Modificada | Alta (7.7) | 53% | 💥 Exploit | F5 NginxOpenrestyFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+9 | 1/6/2021 | 17/6/2026 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. | |
| Modificada | Crítica (9.8) | 1.5% | — | Microfocus Operations Agent | 13/4/2021 | 17/6/2026 | Escalation of privileges vulnerability in Micro Focus Operations Agent, affects versions 12.0x, 12.10, 12.11, 12.12, 12.14 and 12.15. The vulnerability could be exploited to escalate privileges and execute code under the account of the Operations Agent. | |
| Modificada | Crítica (9.8) | 1.7% | — | Microfocus Operations Bridge Manager | 8/4/2021 | 17/6/2026 | Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access. | |
| Modificada | Media (6.5) | 69% | 💥 Exploit | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 31/3/2021 | 12/8/2026 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system. | |
| Analizada | Alta (7.5) | 78% | ⚠ Explotación activa💥 Exploit | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 31/3/2021 | 2/10/2026 | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials. | |
| Modificada | Alta (8.8) | 2.0% | — | Microsoft System Center Operations Manager | 25/2/2021 | 17/6/2026 | System Center Operations Manager Elevation of Privilege Vulnerability | |
| Modificada | Media (4.8) | 0.46% | — | IBM Spectrum Protect Operations Center | 15/2/2021 | 17/6/2026 | IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows certain cache values to be set and dumped to a file. By setting a grossly large cache value and dumping that cached value to a file multiple times, a remote attacker could exploit this vulnerability to… | |
| Modificada | Alta (8) | 0.70% | — | IBM Spectrum Protect Operations Center | 15/2/2021 | 17/6/2026 | IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an unspecified servlet request with specially crafted input parameters, an attacker could exploit this vulnerability to load a malicious .dll… | |
| Modificada | Media (5.4) | 0.59% | — | IBM Spectrum Protect Operations Center | 15/2/2021 | 17/6/2026 | IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obtain a valid session using an attacker controlled IBM Spectrum Protect server, an attacker could exploit this… | |
| Modificada | Crítica (9.8) | 3.5% | — | Microfocus Operations Bridge Manager | 12/2/2021 | 17/6/2026 | Arbitrary code execution vulnerability on Micro Focus Operations Bridge Manager product, affecting versions 10.1x, 10.6x, 2018.05, 2018.11, 2019.05, 2019.11, 2020.05, 2020.10. The vulnerability could allow remote attackers to execute arbitrary code on an OBM server. | |
| Modificada | Alta (8.8) | 0.45% | — | Veritas InfoscaleVeritas Infoscale Operations ManagerVeritas Storage FoundationVeritas Storage Foundation AND High Availability | 6/1/2021 | 17/6/2026 | An issue was discovered in Veritas InfoScale 7.x through 7.4.2 on Windows, Storage Foundation through 6.1 on Windows, Storage Foundation HA through 6.1 on Windows, and InfoScale Operations Manager (aka VIOM) Windows Management Server 7.x through 7.4.2. On start-up, it loads the OpenSSL library from \usr\local\ssl.… | |
| Modificada | Crítica (9.8) | 1.5% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network… | |
| Modificada | Alta (7) | 0.28% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database. | |
| Modificada | Crítica (9.8) | 1.9% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted. | |
| Modificada | Alta (8.8) | 1.5% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges. | |
| Modificada | Alta (8.8) | 1.4% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data. | |
| Modificada | Alta (7.8) | 0.43% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as. | |
| Modificada | Crítica (9.8) | 1.2% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process. | |
| Modificada | Alta (8.8) | 3.1% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines. | |
| Modificada | Crítica (9.8) | 1.1% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some… | |
| Modificada | Media (5.3) | 1.6% | — | IBM Spectrum Protect Operations Center | 23/11/2020 | 17/6/2026 | IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.10.and 7.1.0.000 through 7.1.11 could allow a remote attacker to obtain sensitive information, caused by improper authentication of a websocket endpoint. By using known tools to subscribe to the websocket event stream, an attacker could exploit this… | |
| Modificada | Alta (7.8) | 2.7% | 💥 Exploit | Microfocus Operations BridgeMicrofocus Operations Bridge Manager | 27/10/2020 | 17/6/2026 | Code execution with escalated privileges vulnerability in Micro Focus products Operation Bridge Manager and Operation Bridge (containerized). The vulneravility affects: 1.) Operation Bridge Manager versions: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier… | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | Microfocus Application Performance ManagementMicrofocus Operations BridgeMicrofocus Operations Bridge Manager | 27/10/2020 | 17/6/2026 | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.)… |