Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)7.4%💥 ExploitBrocade Network AdvisorNetapp Brocade Network Advisor22/1/201917/6/2026
A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network…
ModificadaMedia (5.5)0.28%—Google Gvisor17/12/201817/6/2026
Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which allows attackers to cause a denial of service ("physical address not valid" panic) via a crafted application.
ModificadaAlta (7.5)1.4%—IBM Qradar Advisor With Watson5/12/201817/6/2026
IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147810.
ModificadaCrítica (9.8)0.81%—Google Gvisor17/11/201817/6/2026
pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not escape the sandbox) via vectors involving IPC_RMID shmctl calls, because reference counting is mishandled.
ModificadaAlta (7.8)1.6%—Omron Cx-supervisor5/11/201817/6/2026
A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application.
ModificadaAlta (7.8)1.6%—Omron Cx-supervisor5/11/201817/6/2026
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application.
ModificadaBaja (3.3)0.89%—Omron Cx-supervisor5/11/201817/6/2026
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.
ModificadaAlta (7.8)1.1%—Omron Cx-supervisor5/11/201817/6/2026
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object.
ModificadaMedia (6.5)1.1%—Cisco Unified Computing System DirectorCisco Integrated Management Controller Supervisor5/10/201817/6/2026
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of…
ModificadaMedia (4.4)0.34%—Avaya Call Management System Supervisor24/9/201817/6/2026
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
ModificadaMedia (6.8)0.45%—Google Gvisor2/9/201817/6/2026
Google gVisor before 2018-08-23, within the seccomp sandbox, permits access to the renameat system call, which allows attackers to rename files on the host OS.
ModificadaAlta (8.1)2.1%—Dell EMC Data Protection AdvisorDell EMC Integrated Data Protection Appliance10/8/201817/6/2026
Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain…
ModificadaMedia (5.4)4.8%—Apache KafkaRedhat Jboss Middleware Text-only AdvisoriesOracle DatabaseOracle Primavera P6 Enterprise Project Portfolio Management+126/7/201817/6/2026
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
ModificadaMedia (4.8)1.3%—Cisco Integrated Management Controller Supervisor7/6/201817/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the…
ModificadaMedia (5.3)0.34%—Omron Cx-supervisor21/3/201817/6/2026
In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability.
ModificadaMedia (5.3)0.34%—Omron Cx-supervisor21/3/201817/6/2026
In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability.
ModificadaMedia (5.3)0.34%—Omron Cx-supervisor21/3/201817/6/2026
In Omron CX-Supervisor Versions 3.30 and prior, use after free vulnerabilities can be exploited when CX Supervisor parses a specially crafted project file.
ModificadaMedia (5.3)0.36%—Omron Cx-supervisor21/3/201817/6/2026
In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow.
ModificadaMedia (5.3)0.34%—Omron Cx-supervisor21/3/201817/6/2026
In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability.
ModificadaMedia (5.3)0.29%—Omron Cx-supervisor21/3/201817/6/2026
In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets.
ModificadaMedia (5.3)0.36%—Omron Cx-supervisor21/3/201817/6/2026
In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow.
ModificadaCrítica (9.8)2.1%—EMC Data Protection Advisor16/3/201817/6/2026
EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are: "Apollo System Test", "emc.dpa.agent.logon" and "emc.dpa.metrics.logon". An attacker with knowledge of the password could potentially use…
ModificadaAlta (7.8)0.34%—EMC Data Protection Advisor12/3/201817/6/2026
Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with administrative privileges. The affected account is "apollosuperuser." An attacker with local access to the server where DPA Datastore Service…
ModificadaMedia (5.3)0.62%—Tripadvisor Tamobileapp9/3/201817/6/2026
The TripAdvisor app with the versions before TAMobileApp-24.6.4 pre-installed in some Huawei mobile phones have an arbitrary URL loading vulnerability due to insufficient input validation and improper configuration. An attacker may exploit this vulnerability to invoke TripAdvisor to load a specific URL and execute…
ModificadaAlta (8.8)6.7%—EMC Data Protection Advisor19/10/201717/6/2026
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vulnerability. The specific flaw exists within the EMC DPA Application service, which listens on TCP port 9002 by default. When parsing the…
Orbitaley — Vulnerabilidades