Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

482 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)0.84%—Solarwinds Network Performance Monitor21/10/202117/6/2026
Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaAlta (7.4)0.49%—Siemens Sinumerik Analyse Mycondition FirmwareSiemens Sinumerik Analyze Myperformance FirmwareSiemens Sinumerik Integrate Client FirmwareSiemens Sinumerik Integrate FOR Production Firmware+613/7/202117/6/2026
A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 <…
ModificadaMedia (5.4)0.51%—Hitachiabb-powergrids Ellipse Asset Performance Management14/6/202117/6/2026
Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and…
ModificadaMedia (6.7)0.24%—Intel NUC M15 Laptop KIT Lapbc510 FirmwareIntel NUC M15 Laptop KIT Lapbc710 FirmwareIntel NUC 11 Compute Element Cm11ebc4 FirmwareIntel NUC 11 Compute Element Cm11ebi38w Firmware+739/6/202117/6/2026
&nbsp;Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.24%—Intel NUC M15 Laptop KIT Lapbc510 FirmwareIntel NUC M15 Laptop KIT Lapbc710 FirmwareIntel NUC 11 Compute Element Cm11ebc4 FirmwareIntel NUC 11 Compute Element Cm11ebi38w Firmware+739/6/202117/6/2026
Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.7)0.21%—Intel Integrated Performance Primitives CryptographyIntel SGX DcapIntel SGX PSWIntel SGX SDK9/6/202117/6/2026
Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.
ModificadaCrítica (9.8)1.9%—Merge-deep Project Merge-deepNetapp E-series Performance Analyzer2/6/202117/6/2026
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
ModificadaAlta (7.5)2.3%—Css-what Project Css-whatNetapp E-series Performance Analyzer28/5/202117/6/2026
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input.
ModificadaAlta (7.5)2.9%—Trim-newlines Project Trim-newlinesNetapp E-series Performance AnalyzerDebian Linux28/5/202117/6/2026
The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method.
ModificadaMedia (5.3)2.8%—WS Project WSNetapp E-series Performance Analyzer25/5/202117/6/2026
ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In…
ModificadaCrítica (9.8)94%—Solarwinds Network Performance Monitor21/5/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library. The issue results from the lack of…
ModificadaCrítica (9.8)4.5%💥 PoCHandlebarsjs HandlebarsNetapp E-series Performance Analyzer4/5/202117/6/2026
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
ModificadaCrítica (9.8)2.0%—Microfocus Application Performance Management28/4/202117/6/2026
An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9.40, 9.50 and 9.51. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of APM.
ModificadaMedia (4.8)9.9%💥 PoCApache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+5613/4/202125/8/2026
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling…
ModificadaAlta (7.5)54%💥 PoCEclipse JettyOracle Autovue FOR Agile Product Lifecycle ManagementOracle Communications Cloud Native Core PolicyOracle Communications Element Manager+171/4/202117/6/2026
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
ModificadaMedia (5.3)82%💥 ExploitEclipse JettyNetapp Cloud ManagerNetapp E-series Performance AnalyzerNetapp E-series Santricity OS Controller+131/4/202117/6/2026
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive…
ModificadaBaja (2.7)4.2%—Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+191/4/202117/6/2026
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
ModificadaAlta (7.8)0.34%—CA Ehealth Performance Manager26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user. NOTE: This vulnerability only affects products that are no longer…
ModificadaAlta (8.8)0.41%—CA Ehealth Performance Manager26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the FtpCollector executable is run. The code in the…
ModificadaMedia (5.4)0.74%—CA Ehealth Performance Manager26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and perform a Reflected Cross-Site Scripting attack against the platform users. The…
ModificadaMedia (5.9)64%💥 PoCOpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaAlta (7.5)2.1%—Schema-inspector Project Schema-inspectorNetapp E-series Performance AnalyzerNetapp Oncommand Insight19/3/202117/6/2026
Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address validation is vulnerable to a denial-of-service attack where some input (for example…
ModificadaAlta (7.5)83%💥 ExploitGrafanaNetapp E-series Performance Analyzer18/3/202117/6/2026
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
ModificadaAlta (7.5)1.1%—Spdk Storage Performance Development KIT13/3/202117/6/2026
An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI target can crash with a NULL pointer dereference.