Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (10)6.8%—Apache Commons ConfigurationOracle Database ServerOracle Healthcare Foundation13/3/202017/6/2026
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from…
ModificadaCrítica (9.1)1.3%—Johnsoncontrols Metasys Application AND Data ServerJohnsoncontrols Metasys Extended Application AND Data ServerJohnsoncontrols Metasys Lonworks Control ServerJohnsoncontrols Metasys Open Application Server+910/3/202017/6/2026
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX)…
ModificadaCrítica (9.8)2.9%—IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+918/2/202016/6/2026
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.
ModificadaMedia (5.9)0.60%—Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+367/2/202017/6/2026
The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,…
ModificadaAlta (7.5)1.1%—Novell Zenworks Configuration Management25/1/202016/6/2026
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
ModificadaMedia (6.1)0.72%—Novell Zenworks Configuration Management25/1/202016/6/2026
Novell ZENworks Configuration Management before 11.2.4 allows XSS.
ModificadaAlta (7.8)0.29%—Intel Setup AND Configuration Software Platform Discovery Utility16/12/201917/6/2026
Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack.
ModificadaAlta (7.8)0.47%💥 PoCCloudcti HIP Integrator Recognition Configuration Tool14/10/201917/6/2026
CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service (Recognition Update Client Service) via an insecure communication channel (Named Pipe). The data (JSON) sent via this channel is used to import data from CRM software…
ModificadaMedia (5.5)0.38%—Jenkins Configuration AS Code7/8/201917/6/2026
Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.
ModificadaMedia (4.9)0.61%—Jenkins Configuration AS Code31/7/201917/6/2026
Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.
ModificadaMedia (5.4)0.74%—Jenkins Configuration AS Code31/7/201917/6/2026
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain the values of environment variables.
ModificadaMedia (5.5)0.33%—Jenkins Configuration AS Code31/7/201917/6/2026
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
ModificadaMedia (4.3)0.69%—Jenkins Configuration AS Code31/7/201917/6/2026
Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins.
ModificadaBaja (3.3)0.37%—Jenkins Configuration AS Code31/7/201917/6/2026
Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.
ModificadaAlta (7.8)1.7%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+1418/6/201917/6/2026
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will…
ModificadaCrítica (9.1)1.5%—Bosch Access Professional EditionBosch Video ClientBosch Video Management SystemBosch Building Integration System+729/5/201917/6/2026
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC)…
ModificadaCrítica (9.8)2.0%—Bosch Access Professional EditionBosch Video ClientBosch Video Management SystemBosch Building Integration System+929/5/201917/6/2026
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition…
ModificadaAlta (7.5)8.8%—HP Ucmdb Configuration Manager31/12/201817/6/2026
Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities…
ModificadaAlta (7.5)25%—Zohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager6/11/201817/6/2026
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
ModificadaMedia (6.1)0.61%—Knet Cisco Configuration Manager14/9/201817/6/2026
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
ModificadaAlta (7.5)2.4%—HP XP P9000 Configuration ManagerHP XP P9000 Device Manager14/8/201817/6/2026
A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior to 8.6.0-00), Configuration Manager (CM 8.5.0-00 and prior to 8.6.0-00) could be exploited to allow local and remote unauthorized access to sensitive information.
ModificadaMedia (6.1)99%💥 ExploitZohocorp Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+129/6/201817/6/2026
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script…
ModificadaAlta (7.5)6.6%—Zohocorp Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+129/6/201817/6/2026
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server…
ModificadaAlta (8.8)0.90%—Jenkins Configuration AS Code26/6/201817/6/2026
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using…
ModificadaMedia (6.5)0.99%—Jenkins Configuration AS Code26/6/201817/6/2026
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration.
Orbitaley — Vulnerabilidades