Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

439 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.36%—Keyfactor Primekey Ejbca17/11/202217/6/2026
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user.
ModificadaAlta (7.5)0.64%—Intel Quartus Prime11/11/202217/6/2026
XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.
ModificadaAlta (7.8)0.17%—Intel Quartus Prime11/11/202217/6/2026
Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)1.0%—Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware23/9/202217/6/2026
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by…
ModificadaAlta (7.5)1.5%—Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware23/9/202217/6/2026
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to insecure design in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a…
ModificadaCrítica (9.8)2.2%—Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware23/9/202217/6/2026
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability…
ModificadaCrítica (9.8)0.52%—Primekey Ejbca14/9/202217/6/2026
An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process, an order is submitted containing an identifier for one or multiple dnsNames.…
ModificadaCrítica (9.8)4.1%—Mersenne Prime9516/5/202217/6/2026
Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution.
ModificadaAlta (7.5)2.7%💥 PoCPrimeur Spazio11/5/202217/6/2026
The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.
ModificadaMedia (4.8)0.65%—Primekey Signserver21/3/202217/6/2026
An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administrator can update a worker name.
ModificadaCrítica (9.1)0.97%—Rambus Safezone Basic Crypto ModuleFujifilm Apeos C7070 FirmwareFujifilm Apeos C6570 FirmwareFujifilm Apeos C5570 Firmware+8814/3/202217/6/2026
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows…
ModificadaMedia (6.1)1.2%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure17/2/202217/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists…
ModificadaMedia (6.5)1.1%—Cisco Prime Service Catalog10/2/202217/6/2026
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper enforcement of Administrator privilege levels for low-value sensitive data. An attacker with…
ModificadaAlta (7.8)0.24%—Intel Quartus Prime9/2/202217/6/2026
Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)1.1%—Intel Quartus Prime9/2/202217/6/2026
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.
ModificadaAlta (7.8)0.22%—Intel Quartus Prime9/2/202217/6/2026
Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.22%—Intel Quartus Prime9/2/202217/6/2026
Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.26%—Intel Quartus Prime9/2/202217/6/2026
Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.26%—Intel Quartus Prime9/2/202217/6/2026
Improper input validation in a third-party component for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaMedia (5.4)0.60%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure4/11/202117/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.…
ModificadaMedia (4.8)0.59%—Cisco Prime Access Registrar4/11/202117/6/2026
A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied…
ModificadaCrítica (9.8)1.8%—HPE 3par OSHPE Primera 630 FirmwareHPE Primera 650 FirmwareHPE Primera 670 Firmware+211/10/202117/6/2026
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity,…
ModificadaMedia (5.5)0.22%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure2/9/202117/6/2026
A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not…
ModificadaMedia (6.1)0.77%—Cisco Prime Collaboration Provisioning2/9/202117/6/2026
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based…