Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 77% | 💥 Exploit | Microfocus Operation Bridge ManagerMicrofocus Operations Bridge ManagerHP Universal Cmbd FoundationMicrofocus Application Performance Management+3 | 22/10/2020 | 17/6/2026 | Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP… | |
| Modificada | Alta (7.8) | 0.35% | — | Microfocus Operations Agent | 18/9/2020 | 17/6/2026 | Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11. The vulnerability could be exploited to escalate the local privileges and gain root access on the system. | |
| Modificada | Alta (8.8) | 2.7% | — | Microsoft Dynamics 365 FOR Finance AND Operations | 11/9/2020 | 17/6/2026 | <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim server.</p> <p>An authenticated attacker with… | |
| Modificada | Crítica (9.8) | 2.5% | — | IBM Spectrum Protect Operations Center | 2/9/2020 | 17/6/2026 | IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the system, caused by improper validation of data prior to export. IBM X-Force ID: 186782. | |
| Modificada | Alta (8) | 2.8% | — | Microsoft Dynamics 365 FOR Finance AND Operations | 17/8/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim server. An authenticated attacker with privileges to… | |
| Modificada | Media (5.7) | 0.71% | — | Vmware Tanzu Application Service FOR Virtual MachinesVmware Operations Manager | 31/7/2020 | 17/6/2026 | VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the unredacted logs are available to… | |
| Modificada | Media (5.4) | 0.67% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 28/7/2020 | 17/6/2026 | IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… | |
| Modificada | Media (5.4) | 0.56% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 28/7/2020 | 17/6/2026 | IBM Intelligent Operations Center for Emergency Management, Intelligent Operations Center (IOC), and IBM Water Operations for Waternamics are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… | |
| Modificada | Alta (8.1) | 0.42% | — | IBM Marketing Operations | 20/7/2020 | 17/6/2026 | Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information. | |
| Modificada | Alta (7.7) | 3.1% | — | Redislabs RedisOracle Communications Operations MonitorSuse Linux EnterpriseDebian Linux | 15/6/2020 | 17/6/2026 | An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which… | |
| Modificada | Media (5.4) | 1.3% | — | Microsoft System Center Operations Manager | 9/6/2020 | 17/6/2026 | A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'. | |
| Analizada | Media (6.1) | 85% | ⚠ Explotación activa💥 Exploit | JqueryDebian LinuxFedoraproject FedoraDrupal+48 | 29/4/2020 | 17/6/2026 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. | |
| Modificada | Alta (7.5) | 1.4% | — | Vmware Vrealize Operations | 19/2/2020 | 17/6/2026 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize… | |
| Modificada | Alta (8.6) | 1.5% | — | Vmware Vrealize Operations | 19/2/2020 | 17/6/2026 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter… | |
| Modificada | Crítica (9.8) | 2.3% | — | Vmware Vrealize Operations | 19/2/2020 | 17/6/2026 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize… | |
| Modificada | Alta (7.5) | 0.91% | — | Redhat Jboss BrmsRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss Operations Network+2 | 23/1/2020 | 16/6/2026 | EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation. | |
| Modificada | Media (6.5) | 1.1% | — | Pivotal Software Operations Manager | 9/1/2020 | 17/6/2026 | Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. | |
| Modificada | Media (6.1) | 1.3% | — | Drupal Views Builk Operations | 25/11/2019 | 16/6/2026 | Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS)… | |
| Modificada | Media (6.5) | 0.77% | — | Microfocus Operations Agent | 18/11/2019 | 17/6/2026 | XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Operations Agent. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Media (6.5) | 0.87% | — | Redhat Jboss Operations Network | 8/11/2019 | 16/6/2026 | In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON. | |
| Modificada | Alta (7.1) | 0.31% | — | Redhat RHQ Mongo DB Drift ServerRedhat Jboss Operations Network | 4/11/2019 | 16/6/2026 | An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files. | |
| Modificada | Alta (8) | 0.53% | — | Redhat Jboss Operations Network | 30/10/2019 | 16/6/2026 | A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user. | |
| Modificada | Alta (8.8) | 2.5% | — | Broadcom CA Performance ManagementBroadcom Network Operations | 17/10/2019 | 17/6/2026 | CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security. | |
| Modificada | Media (5.3) | 2.8% | — | Tcpdump LibpcapDebian LinuxOpensuse LeapOracle Communications Operations Monitor+7 | 3/10/2019 | 17/6/2026 | sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory. |