Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3072▲ 483 respecto a la semana anterior
Críticas / altas1456▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

5122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)0.64%—Asustor Data Master17/8/202317/6/2026
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
ModificadaAlta (8.8)0.66%—Asustor Data Master17/8/202317/6/2026
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.
ModificadaAlta (8.8)1.6%—Asustor Data Master17/8/202317/6/2026
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below…
ModificadaCrítica (9.8)0.47%—Cyberpower Powerpanel ServerDataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 Firmware+1914/8/202317/6/2026
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary…
ModificadaAlta (7.5)0.69%—Dataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4a-n20 Firmware+1814/8/202317/6/2026
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid authorization token and read information relating…
ModificadaMedia (6.7)0.30%—Dataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4a-n20 Firmware+1814/8/202317/6/2026
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to read, modify, or delete arbitrary…
ModificadaAlta (7.2)0.78%—Cyberpower Powerpanel ServerDataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 Firmware+1914/8/202317/6/2026
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted vulnerable binary, including the…
ModificadaAlta (8.8)1.3%—Cyberpower Powerpanel ServerDataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 Firmware+1914/8/202317/6/2026
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.
ModificadaCrítica (9.8)0.95%—Dataprobe Iboot-pdu4a-c10 FirmwareDataprobe Iboot-pdu4a-c20 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4a-n20 Firmware+1814/8/202317/6/2026
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation allows the malicious agent to take…
ModificadaAlta (7.3)0.17%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.18%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)0.91%—Fasterxml Jackson-dataformats-text8/8/202317/6/2026
Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
ModificadaAlta (8.8)0.73%—Esds.co Emagic Data Center Management8/8/202317/6/2026
This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized access to the targeted system.
ModificadaAlta (8.8)34%💥 ExploitEsds.co Emagic Data Center Management8/8/202317/6/2026
Esta vulnerabilidad existe en ESDS Emagic Data Center Management Suit debido a la falta de sanitización de entrada en su componente Ping. Un atacante remoto autenticado podría explotar esto inyectando comandos del sistema operativo en el sistema objetivo. La explotación exitosa de esta vulnerabilidad podría permitir…
ModificadaCrítica (9.8)1.0%—Datadoghq Import-in-the-middle7/8/202317/6/2026
import-in-the-middle is a module loading interceptor specifically for ESM modules. The import-in-the-middle loader works by generating a wrapper module on the fly. The wrapper uses the module specifier to load the original module and add some wrapping code. Prior to version 1.4.2, it allows for remote code execution…
ModificadaMedia (6.5)2.8%—MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+37/8/202317/6/2026
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
ModificadaAlta (7.8)0.16%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+83/8/202317/6/2026
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability…
ModificadaAlta (7.5)0.65%—FreebsdNetapp Clustered Data Ontap1/8/202317/6/2026
Un conjunto de paquetes ipv6 cuidadosamente diseñados puede desencadenar un desbordamiento de enteros en el cálculo del campo de longitud de la carga útil de un paquete reensamblado por fragmentos. Esto permite a un atacante desencadenar un kernel panic, resultando en una denegación de servicio.
ModificadaCrítica (9.8)1.1%—Dataease25/7/202317/6/2026
DataEase es una herramienta de análisis de visualización de datos de código abierto. Antes de la versión 1.18.9, DataEase tiene una vulnerabilidad de inyección SQL que puede eludir las listas negras. La vulnerabilidad se ha corregido en v1.18.9. No hay soluciones alternativas conocidas.
ModificadaMedia (5.4)0.43%—Dataease25/7/202317/6/2026
DataEase es una herramienta de análisis de visualización de datos de código abierto. Antes de la versión 1.18.9, el panel y el conjunto de datos de DataEase tenían una vulnerabilidad de Cross-Site Scripting Almacenado. La vulnerabilidad se ha corregido en v1.18.9. No hay soluciones alternativas conocidas.
ModificadaMedia (4.9)0.52%—Datalust SEQ22/7/202317/6/2026
Datalust Seq before 2023.2.9489 allows insertion of sensitive information into an externally accessible file or directory. This is exploitable only when external (SQL Server or PostgreSQL) metadata storage is used. Exploitation can only occur from a high-privileged user account.
ModificadaMedia (5.5)0.21%—Edinet-fsa Xbrl Data Create19/7/202317/6/2026
XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.
ModificadaAlta (7.5)0.54%—IBM Cloud PAK FOR Data19/7/202317/6/2026
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 247905.
ModificadaAlta (7.5)0.57%—IBM Cloud PAK FOR Data19/7/202317/6/2026
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.
ModificadaAlta (7.5)0.66%—IBM Cloud PAK FOR Data19/7/202317/6/2026
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks. IBM X-Force ID: 247896.