Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
386 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.93% | — | Broadcom Vmware Nsx-t Data CenterVmware Cloud Foundation | 20/10/2020 | 17/6/2026 | VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node. | |
| Modificada | Media (5.3) | 76% | 💥 Exploit | Atlassian Jira Data CenterAtlassian Jira Server | 21/9/2020 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0… | |
| Modificada | Media (5.3) | 100% | 💥 Exploit | Atlassian Data CenterAtlassian JiraAtlassian Jira Server | 17/9/2020 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0. | |
| Modificada | Alta (7.5) | 3.1% | — | Atlassian JiraAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Software Data Center | 1/9/2020 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0. | |
| Modificada | Media (5.4) | 0.62% | — | Cisco Data Center Network Manager | 26/8/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Media (6.3) | 0.80% | — | Cisco Data Center Network Manager | 26/8/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the device. The vulnerability exists because the affected software… | |
| Modificada | Media (6.5) | 1.8% | — | Cisco Data Center Network Manager | 26/8/2020 | 17/6/2026 | A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker with a… | |
| Modificada | Media (5.5) | 0.29% | — | Cisco Data Center Network Manager | 26/8/2020 | 17/6/2026 | A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obtain confidential information from an affected device. The vulnerability is due to insufficient protection of confidential information on an affected device. An attacker at any privilege level could… | |
| Modificada | Alta (8.1) | 0.97% | — | Cisco Data Center Network Manager | 26/8/2020 | 17/6/2026 | A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the API. An attacker could exploit… | |
| Modificada | Media (5.4) | 0.62% | — | Cisco Data Center Network Manager | 26/8/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of the affected software. The vulnerability exists because the web-based management… | |
| Modificada | Media (4.8) | 0.62% | — | Cisco Data Center Network Manager | 26/8/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient input validation by the web-based management… | |
| Modificada | Media (6.7) | 0.35% | — | Intel SSD Data Center Tool | 13/8/2020 | 17/6/2026 | Improper access control in the installer for Intel(R) SSD DCT versions before 3.0.23 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.3) | 0.74% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this… | |
| Modificada | Media (5.3) | 1.2% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. The vulnerability is due to missing authentication on a specific part of the web-based management interface. An… | |
| Modificada | Media (6.1) | 0.72% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Alta (8.8) | 2.0% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. The vulnerability is due to insufficient authorization of certain API functions. An attacker could… | |
| Modificada | Alta (8.2) | 0.79% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in user. The vulnerability is due to insufficient validation of user-supplied input… | |
| Modificada | Alta (8.8) | 7.0% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to a lack of proper input validation of paths that are embedded within archive files. An attacker could… | |
| Modificada | Crítica (9.8) | 2.3% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different installations share a static encryption… | |
| Modificada | Alta (8.8) | 1.0% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.8) | 1.2% | — | Cisco Data Center Network Manager | 31/7/2020 | 17/6/2026 | A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions on an affected device. The vulnerability is due to a failure in the software to perform proper authentication. An attacker… | |
| Modificada | Media (5.4) | 1.2% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 24/7/2020 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2. | |
| Modificada | Alta (7.8) | 0.60% | — | Cisco Data Center Network Manager | 16/7/2020 | 17/6/2026 | A vulnerability in the CLI of Cisco Data Center Network Manager (DCNM) could allow an authenticated, local attacker to elevate privileges to root and execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient restrictions during the execution of an affected CLI command. An… | |
| Modificada | Media (4.8) | 0.62% | — | Cisco Data Center Network Manager | 16/7/2020 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Media (4.8) | 0.62% | — | Cisco Data Center Network Manager | 16/7/2020 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. These vulnerabilities are due to insufficient validation of… |