Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)298▼ 212 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Npci Bharat Interface FOR Money (bhim) | 24/8/2018 | 17/6/2026 | The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication. | |
| Modificada | Alta (7.5) | 1.3% | — | Npci Bharat Interface FOR Money (bhim) | 24/8/2018 | 17/6/2026 | The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access. | |
| Modificada | Alta (7.8) | 1.2% | — | HP Restful Interface Tool | 6/8/2018 | 17/6/2026 | A remote execution of arbitrary code vulnerability has been identified in HPE RESTful Interface Tool 1.5, 2.0 (hprest-1.5-79.x86_64.rpm, ilorest-2.0-403.x86_64.rpm). The issue is resolved in iLOREST v2.1 or subsequent versions. | |
| Modificada | Media (4.3) | 0.58% | — | SAP NetweaverSAP UI InfraSAP User Interface Technology | 10/7/2018 | 17/6/2026 | A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User… | |
| Modificada | Crítica (9.8) | 2.8% | — | Opendaylight Sdninterfaceapp | 20/6/2018 | 17/6/2026 | A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. SDNInterface has been deprecated in OpenDayLight since it was last used in the final Carbon series release. In addition to the component not… | |
| Modificada | Media (6.5) | 1.1% | — | Clusterlabs Pacemaker Command Line InterfaceRedhat Enterprise Linux | 12/4/2018 | 17/6/2026 | pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth directory exists, an authenticated attacker with write permissions could… | |
| Modificada | Alta (7.5) | 1.9% | — | Clusterlabs Pacemaker Command Line InterfaceDebian LinuxRedhat Enterprise Linux Server EUS | 12/4/2018 | 17/6/2026 | pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their… | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (8.8) | 3.0% | 💥 Exploit | PloneZope Management Interface | 25/9/2017 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x. | |
| Modificada | Media (4) | 0.46% | — | Oracle Hospitality Suite8 Property Interfaces | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Hospitality Property Interfaces executes to… | |
| Modificada | Media (6.5) | 1.9% | — | Oracle Hospitality Suite8 Property Interfaces | 8/8/2017 | 17/6/2026 | Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality Property Interfaces.… | |
| Modificada | Media (5.3) | 1.5% | — | Oracle Payment Interface | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Payment Interface component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 6.1.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payment Interface. Successful attacks of… | |
| Modificada | Alta (7.5) | 1.3% | — | Eaton Xcomfort Ethernet Communication Interface | 14/3/2017 | 17/6/2026 | An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating. | |
| Modificada | Alta (7.8) | 0.31% | — | Lenovo System Interface Foundation | 29/11/2016 | 17/6/2026 | During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges. | |
| Modificada | Media (6.5) | 1.4% | — | Oracle Siebel User Interface Framework | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Siebel Apps - Customer Order Management component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality via unknown vectors. | |
| Modificada | Media (5.5) | 0.46% | — | HP Restful Interface Tool | 30/5/2016 | 17/6/2026 | HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5) | 1.6% | — | SAP Network Interface Router | 4/11/2014 | 17/6/2026 | Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (resource consumption) via crafted requests. | |
| Modificada | Media (6.8) | 11% | — | Microsoft Debug Interface Access Software Development KITMicrosoft Visual Studio | 20/5/2014 | 17/6/2026 | msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-call address, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)… | |
| Modificada | Alta (9.7) | 3.8% | 💥 Exploit | Broadcom Pipa C211 WEB InterfaceBroadcom Pipa C211 | 14/5/2014 | 17/6/2026 | cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors. | |
| Modificada | Media (4.7) | 0.30% | — | Osisoft PI Interface | 12/4/2014 | 16/6/2026 | The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows physically proximate attackers to cause a denial of service (interface shutdown) via crafted input over a serial line. | |
| Modificada | Alta (7.1) | 1.5% | — | Osisoft PI Interface | 12/4/2014 | 16/6/2026 | The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows remote attackers to cause a denial of service (interface shutdown) via a crafted TCP packet. | |
| Modificada | Media (5) | 2.6% | — | SAP Network Interface Router | 13/12/2013 | 17/6/2026 | SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vectors. | |
| Modificada | Media (6.8) | 2.7% | — | SAP Network Interface Router | 20/11/2013 | 17/6/2026 | Heap-based buffer overflow in SAP Network Interface Router (SAProuter) 7.30 allows remote attackers to cause a denial of service and execute arbitrary code via crafted NI Route messages. | |
| Modificada | Media (5) | 1.4% | — | Osisoft PI Interface | 22/8/2013 | 16/6/2026 | The OSIsoft PI Interface for IEEE C37.118 before 1.0.6.158 allows remote attackers to cause a denial of service (instance shutdown and data-collection outage) via crafted C37.118 configuration packets that trigger an invalid read operation. | |
| Modificada | Media (5) | 1.4% | — | Osisoft PI Interface | 22/8/2013 | 16/6/2026 | The OSIsoft PI Interface for IEEE C37.118 before 1.0.6.158 allows remote attackers to cause a denial of service (memory consumption or memory corruption, instance shutdown, and data-collection outage) via crafted C37.118 configuration packets. |