Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A…
ModificadaAlta (8.8)1.4%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected…
ModificadaAlta (7.5)1.9%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on…
ModificadaAlta (7.2)1.8%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request…
ModificadaAlta (7.2)3.8%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software.…
ModificadaAlta (7.8)0.41%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input…
ModificadaAlta (7.2)3.3%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an affected device. The vulnerability is due to improper…
ModificadaAlta (8.8)3.6%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied…
ModificadaAlta (8.8)2.6%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of command input by…
ModificadaAlta (8.1)1.7%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this…
ModificadaAlta (7.2)3.5%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. An attacker would need to have valid administrator credentials on the…
ModificadaAlta (7.2)2.8%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient…
ModificadaAlta (7.5)2.0%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing…
ModificadaAlta (7.5)11%💥 PoCFasterxml Jackson-databindDebian LinuxFedoraproject FedoraApache Drill+1430/7/201917/6/2026
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
ModificadaCrítica (9.8)5.2%—PythonRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+107/6/201917/6/2026
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application…
ModificadaMedia (6.7)0.61%—Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+2313/5/201917/6/2026
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based…
ModificadaMedia (5)0.83%—Omron Cx-supervisor12/2/201917/6/2026
When CX-Supervisor (Versions 3.42 and prior) processes project files and tampers with the value of an offset, an attacker can force the application to read a value outside of an array.
ModificadaAlta (7.3)1.2%—Omron Cx-supervisor12/2/201917/6/2026
An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
ModificadaAlta (7.3)1.5%—Omron Cx-supervisor28/1/201917/6/2026
An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application.
ModificadaAlta (7.3)1.5%—Omron Cx-supervisor22/1/201917/6/2026
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
ModificadaAlta (8.8)2.4%—Omron Cx-supervisor22/1/201917/6/2026
Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the…
ModificadaMedia (5)0.75%—Omron Cx-supervisor22/1/201917/6/2026
An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file.
ModificadaAlta (8.8)2.4%—Omron Cx-supervisor22/1/201917/6/2026
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
ModificadaAlta (7.5)1.7%—Brocade Network AdvisorNetapp Brocade Network Advisor22/1/201917/6/2026
A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the…
ModificadaCrítica (9.8)3.3%—Brocade Network AdvisorNetapp Brocade Network Advisor22/1/201917/6/2026
A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited to execute arbitrary OS Commands.