Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 7.4% | 💥 Exploit | Brocade Network AdvisorNetapp Brocade Network Advisor | 22/1/2019 | 17/6/2026 | A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network… | |
| Modificada | Media (5.5) | 0.28% | — | Google Gvisor | 17/12/2018 | 17/6/2026 | Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Qradar Advisor With Watson | 5/12/2018 | 17/6/2026 | IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147810. | |
| Modificada | Crítica (9.8) | 0.81% | — | Google Gvisor | 17/11/2018 | 17/6/2026 | pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not escape the sandbox) via vectors involving IPC_RMID shmctl calls, because reference counting is mishandled. | |
| Modificada | Alta (7.8) | 1.6% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application. | |
| Modificada | Alta (7.8) | 1.6% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application. | |
| Modificada | Baja (3.3) | 0.89% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array. | |
| Modificada | Alta (7.8) | 1.1% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object. | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Unified Computing System DirectorCisco Integrated Management Controller Supervisor | 5/10/2018 | 17/6/2026 | A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of… | |
| Modificada | Media (4.4) | 0.34% | — | Avaya Call Management System Supervisor | 24/9/2018 | 17/6/2026 | A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x. | |
| Modificada | Media (6.8) | 0.45% | — | Google Gvisor | 2/9/2018 | 17/6/2026 | Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS. | |
| Modificada | Alta (8.1) | 2.1% | — | Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance | 10/8/2018 | 17/6/2026 | Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain… | |
| Modificada | Media (5.4) | 4.8% | — | Apache KafkaRedhat Jboss Middleware Text-only AdvisoriesOracle DatabaseOracle Primavera P6 Enterprise Project Portfolio Management+1 | 26/7/2018 | 17/6/2026 | In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss. | |
| Modificada | Media (4.8) | 1.3% | — | Cisco Integrated Management Controller Supervisor | 7/6/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the… | |
| Modificada | Media (5.3) | 0.34% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability. | |
| Modificada | Media (5.3) | 0.34% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability. | |
| Modificada | Media (5.3) | 0.34% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, use after free vulnerabilities can be exploited when CX Supervisor parses a specially crafted project file. | |
| Modificada | Media (5.3) | 0.36% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow. | |
| Modificada | Media (5.3) | 0.34% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability. | |
| Modificada | Media (5.3) | 0.29% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets. | |
| Modificada | Media (5.3) | 0.36% | — | Omron Cx-supervisor | 21/3/2018 | 17/6/2026 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow. | |
| Modificada | Crítica (9.8) | 2.1% | — | EMC Data Protection Advisor | 16/3/2018 | 17/6/2026 | EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are: "Apollo System Test", "emc.dpa.agent.logon" and "emc.dpa.metrics.logon". An attacker with knowledge of the password could potentially use… | |
| Modificada | Alta (7.8) | 0.34% | — | EMC Data Protection Advisor | 12/3/2018 | 17/6/2026 | Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with administrative privileges. The affected account is "apollosuperuser." An attacker with local access to the server where DPA Datastore Service… | |
| Modificada | Media (5.3) | 0.62% | — | Tripadvisor Tamobileapp | 9/3/2018 | 17/6/2026 | The TripAdvisor app with the versions before TAMobileApp-24.6.4 pre-installed in some Huawei mobile phones have an arbitrary URL loading vulnerability due to insufficient input validation and improper configuration. An attacker may exploit this vulnerability to invoke TripAdvisor to load a specific URL and execute… | |
| Modificada | Alta (8.8) | 6.7% | — | EMC Data Protection Advisor | 19/10/2017 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vulnerability. The specific flaw exists within the EMC DPA Application service, which listens on TCP port 9002 by default. When parsing the… |