Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)298▼ 212 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.1%—Npci Bharat Interface FOR Money (bhim)24/8/201817/6/2026
The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.
ModificadaAlta (7.5)1.3%—Npci Bharat Interface FOR Money (bhim)24/8/201817/6/2026
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.
ModificadaAlta (7.8)1.2%—HP Restful Interface Tool6/8/201817/6/2026
A remote execution of arbitrary code vulnerability has been identified in HPE RESTful Interface Tool 1.5, 2.0 (hprest-1.5-79.x86_64.rpm, ilorest-2.0-403.x86_64.rpm). The issue is resolved in iLOREST v2.1 or subsequent versions.
ModificadaMedia (4.3)0.58%—SAP NetweaverSAP UI InfraSAP User Interface Technology10/7/201817/6/2026
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User…
ModificadaCrítica (9.8)2.8%—Opendaylight Sdninterfaceapp20/6/201817/6/2026
A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. SDNInterface has been deprecated in OpenDayLight since it was last used in the final Carbon series release. In addition to the component not…
ModificadaMedia (6.5)1.1%—Clusterlabs Pacemaker Command Line InterfaceRedhat Enterprise Linux12/4/201817/6/2026
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth directory exists, an authenticated attacker with write permissions could…
ModificadaAlta (7.5)1.9%—Clusterlabs Pacemaker Command Line InterfaceDebian LinuxRedhat Enterprise Linux Server EUS12/4/201817/6/2026
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their…
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent2/3/201817/6/2026
SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (8.8)3.0%💥 ExploitPloneZope Management Interface25/9/201717/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
ModificadaMedia (4)0.46%—Oracle Hospitality Suite8 Property Interfaces8/8/201717/6/2026
Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Hospitality Property Interfaces executes to…
ModificadaMedia (6.5)1.9%—Oracle Hospitality Suite8 Property Interfaces8/8/201717/6/2026
Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Property Interfaces.…
ModificadaMedia (5.3)1.5%—Oracle Payment Interface8/8/201717/6/2026
Vulnerability in the Oracle Payment Interface component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 6.1.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payment Interface. Successful attacks of…
ModificadaAlta (7.5)1.3%—Eaton Xcomfort Ethernet Communication Interface14/3/201717/6/2026
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating.
ModificadaAlta (7.8)0.31%—Lenovo System Interface Foundation29/11/201617/6/2026
During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges.
ModificadaMedia (6.5)1.4%—Oracle Siebel User Interface Framework25/10/201617/6/2026
Unspecified vulnerability in the Siebel Apps - Customer Order Management component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality via unknown vectors.
ModificadaMedia (5.5)0.46%—HP Restful Interface Tool30/5/201617/6/2026
HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.
ModificadaMedia (5)1.6%—SAP Network Interface Router4/11/201417/6/2026
Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (resource consumption) via crafted requests.
ModificadaMedia (6.8)11%—Microsoft Debug Interface Access Software Development KITMicrosoft Visual Studio20/5/201417/6/2026
msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-call address, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…
ModificadaAlta (9.7)3.8%💥 ExploitBroadcom Pipa C211 WEB InterfaceBroadcom Pipa C21114/5/201417/6/2026
cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors.
ModificadaMedia (4.7)0.30%—Osisoft PI Interface12/4/201416/6/2026
The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows physically proximate attackers to cause a denial of service (interface shutdown) via crafted input over a serial line.
ModificadaAlta (7.1)1.5%—Osisoft PI Interface12/4/201416/6/2026
The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows remote attackers to cause a denial of service (interface shutdown) via a crafted TCP packet.
ModificadaMedia (5)2.6%—SAP Network Interface Router13/12/201317/6/2026
SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vectors.
ModificadaMedia (6.8)2.7%—SAP Network Interface Router20/11/201317/6/2026
Heap-based buffer overflow in SAP Network Interface Router (SAProuter) 7.30 allows remote attackers to cause a denial of service and execute arbitrary code via crafted NI Route messages.
ModificadaMedia (5)1.4%—Osisoft PI Interface22/8/201316/6/2026
The OSIsoft PI Interface for IEEE C37.118 before 1.0.6.158 allows remote attackers to cause a denial of service (instance shutdown and data-collection outage) via crafted C37.118 configuration packets that trigger an invalid read operation.
ModificadaMedia (5)1.4%—Osisoft PI Interface22/8/201316/6/2026
The OSIsoft PI Interface for IEEE C37.118 before 1.0.6.158 allows remote attackers to cause a denial of service (memory consumption or memory corruption, instance shutdown, and data-collection outage) via crafted C37.118 configuration packets.
Orbitaley — Vulnerabilidades