Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

1570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.14%—Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+17/4/202617/6/2026
Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -…
AnalizadaCrítica (9.8)0.61%—Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+17/4/202617/6/2026
Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -…
AnalizadaMedia (6.9)0.62%—Tensoropera Fedml5/4/202624/7/2026
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not…
AnalizadaBaja (2.1)0.70%—Tensoropera Fedml5/4/202624/7/2026
A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the argument dataSet results in path traversal. The attack is possible to be carried out remotely. The exploit has been…
AnalizadaAlta (8.6)0.10%—Microfocus Operations Agent31/3/202624/7/2026
A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability
AnalizadaBaja (2.7)0.48%—Aicentre Federated Learning AND Interoperability Platform27/3/202617/6/2026
Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-stuffing attacks.…
En análisisBaja (3.3)0.19%—Codra Panorama Collaborative Operation & ExecutionCodra Panorama COMCodra Panorama E2Codra Panorama H225/3/202617/6/2026
Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt.
AnalizadaBaja (1.9)0.27%—Tenable Operational Technology Exposure24/3/202618/8/2026
An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to…
AplazadaMedia (6.4)0.24%—Tour Activity Operator Plugin FOR TourcmsAI21/3/202617/6/2026
The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the tourcms_doc_link shortcode in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AnalizadaAlta (8.8)1.1%—Microsoft System Center Operations Manager10/3/202617/6/2026
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.5)0.19%—Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation10/3/202624/6/2026
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
AnalizadaMedia (4.9)0.35%—Suse Rancher Backup AND Restore Operator4/3/202617/6/2026
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
ModificadaMedia (5.9)0.19%—IBM APP Connect Enterprise Certified Containers OperandsIBM APP Connect Operator3/3/202617/6/2026
IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0.20, and IBM App Connect Enterprise Certified Containers Operands versions CD 12.0.11.2‑r1 through 12.0.12.5‑r1 and 13.0.1.0‑r1 through 13.0.6.1‑r1, and LTS versions 12.0.12‑r1 through 12.0.12‑r20,…
AnalizadaAlta (7.2)0.71%—Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform25/2/202617/6/2026
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of…
AnalizadaCrítica (9)0.42%—Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform25/2/202617/6/2026
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the…
AnalizadaAlta (8.1)18%⚠ Explotación activaVmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform25/2/202617/6/2026
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the…
ModificadaAlta (8.1)0.42%—Linuxfoundation Strimzi Kafka Operator21/2/202615/7/2026
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly configures the trusted certificates for mTLS…
AplazadaMedia (4)0.11%—IBM MQ OperatorAIIBM MQ AdvancedAI17/2/202617/6/2026
IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2, CD, and LTS 9.3.x–9.4.x releases) contain a vulnerability where log messages are not properly neutralized before being written to log files. This flaw could allow an unauthorized user to inject…
AplazadaMedia (4.3)0.15%—IBM Operations Analytics LOG AnalysisAIIBM Smartcloud Analytics LOG AnalysisAI4/2/202617/6/2026
IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are vulnerable to a cross-site request forgery (CSRF) vulnerability that could allow an attacker to trick a trusted user into performing unauthorized actions.
AplazadaBaja (2.7)0.35%—Hillstone Networks Operation AND Maintenance Security GatewayAI4/2/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Upload a Web Shell to a Web Server.This issue affects Operation and Maintenance Security Gateway: V5.5ST00001B113.
AnalizadaAlta (8.5)0.14%—Broadcom Fabric Operating System3/2/202617/6/2026
A vulnerability in Brocade Fabric OS before 9.2.1c3 could allow elevating the privileges of the local authenticated user to “root” using the export option of seccertmgmt and seccryptocfg commands.
AnalizadaMedia (4.6)0.20%—Broadcom Fabric Operating System3/2/202617/6/2026
A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories.
AnalizadaMedia (4.6)0.20%—Broadcom Fabric Operating System3/2/202617/6/2026
A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.
AnalizadaAlta (8.2)0.22%—Broadcom Fabric Operating System3/2/202617/6/2026
A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely stored file contents including the history command.
AnalizadaAlta (8.4)0.55%—Broadcom Fabric Operating System3/2/202617/6/2026
A vulnerability in Brocade Fabric OS versions before 9.2.1c2 could allow an administrator-level user to execute the bind command, to escalate privileges and bypass security controls allowing the execution of arbitrary commands.