Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

5122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.23%—Mlit National Land Numerical Information Data Conversion Tool11/4/202317/6/2026
National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.
ModificadaAlta (8.2)1.2%—Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+210/4/202317/6/2026
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,…
ModificadaAlta (7.5)0.87%—Cisco Packet Data Network Gateway5/4/202317/6/2026
A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection. This vulnerability is due to the VPP improperly handling a malformed packet. An attacker could exploit this…
ModificadaMedia (5.4)0.43%—Dell Streaming Data Platform5/4/202317/6/2026
Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks.
ModificadaAlta (7.1)0.18%—Nvidia Data Center GPU Manager1/4/202317/6/2026
NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buffer overflow through the bound socket. A successful exploit of this vulnerability may lead to denial of service and data tampering.
ModificadaMedia (4.8)0.60%—Datagear31/3/202317/6/2026
A vulnerability was found in DataGear up to 4.5.1. It has been classified as problematic. This affects an unknown part of the component Diagram Type Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (5.5)1.2%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+730/3/202317/6/2026
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the…
ModificadaMedia (5.9)1.9%—Haxx LibcurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapBroadcom Brocade Fabric Operating System Firmware+530/3/202317/6/2026
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads…
ModificadaAlta (8.8)2.0%—Haxx CurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+530/3/202317/6/2026
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation…
ModificadaAlta (7.5)0.28%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.
ModificadaAlta (8.8)0.90%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.
ModificadaCrítica (9.8)0.92%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.
ModificadaAlta (8.8)0.91%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.
ModificadaAlta (8.8)0.84%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.
ModificadaCrítica (9.8)1.4%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.
ModificadaCrítica (9.8)62%💥 ExploitRocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the…
ModificadaCrítica (9.8)61%💥 ExploitRocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.
ModificadaCrítica (9.8)1.4%—Rocketsoftware UnidataRocketsoftware Universe29/3/202317/6/2026
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.
ModificadaAlta (8.8)1.3%—Dataease28/3/202317/6/2026
DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may lead to remote code execution. This vulnerability has been fixed in…
ModificadaCrítica (9.8)1.5%—Databasir28/3/202317/6/2026
Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.
ModificadaCrítica (9.8)0.88%—Dataease25/3/202317/6/2026
Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.
ModificadaMedia (6.1)0.46%—Dataease24/3/202317/6/2026
Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been fixed in version…
ModificadaMedia (5.4)0.44%—Pluginus Wordpress Meta Data AND Taxonomies Filter22/3/202317/6/2026
The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticated user.
ModificadaMedia (6.1)0.63%—Datagear22/3/202317/6/2026
A vulnerability was found in DataGear up to 1.11.1 and classified as problematic. This issue affects some unknown processing of the component Graph Dataset Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.92%—Datagear22/3/202317/6/2026
A vulnerability, which was classified as critical, was found in DataGear up to 4.5.0. This affects an unknown part of the file /analysisProject/pagingQueryData. The manipulation of the argument queryOrder leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…