Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Netflix Chaos Monkey | 3/12/2020 | 17/6/2026 | Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks. | |
| Modificada | Media (6.5) | 0.94% | — | Netflix Dispatch | 9/11/2020 | 17/6/2026 | The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a participant in a restricted incident, and users able to view restricted incidents via the search feature. If your install has followed the secure deployment guidelines… | |
| Modificada | Media (5.4) | 0.57% | — | Netflix Dispatch | 9/11/2020 | 17/6/2026 | There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user. | |
| Modificada | Crítica (9.8) | 1.4% | — | Konzept-ix Publixone | 27/10/2020 | 17/6/2026 | A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user accounts, and have unspecified other impact. | |
| Modificada | Media (6.1) | 0.82% | — | Konzept-ix Publixone | 27/10/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, ixedit/editor_component.jsp, or the login form. | |
| Modificada | Media (6.5) | 0.94% | — | Konzept-ix Publixone | 27/10/2020 | 17/6/2026 | A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files. | |
| Modificada | Alta (7.5) | 1.2% | — | Konzept-ix Publixone | 27/10/2020 | 17/6/2026 | konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter. | |
| Modificada | Crítica (9.8) | 1.3% | — | Konzept-ix Publixone | 27/10/2020 | 17/6/2026 | konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens. | |
| Modificada | Media (6.5) | 10% | 💥 Exploit | Vmware Spring Cloud Netflix | 7/8/2020 | 17/6/2026 | Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to… | |
| Modificada | Crítica (9.8) | 1.9% | — | Netflix Titus | 14/7/2020 | 17/6/2026 | Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error… | |
| Modificada | Crítica (9.8) | 1.7% | — | Netflix Conductor | 16/6/2020 | 17/6/2026 | Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message template being passed to… | |
| Modificada | Media (6.7) | 0.33% | — | Lenovo 330-14ast FirmwareLenovo 330-15ast FirmwareLenovo 330-17ast FirmwareLenovo 340c-15api Firmware+168 | 9/6/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. | |
| Modificada | Alta (8.1) | 1.4% | — | LIX Project LIX | 21/3/2020 | 17/6/2026 | lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream so that the Location header is associated with attacker-controlled executable content in the postDownload field. | |
| Modificada | Media (6.1) | 0.97% | — | Blixhq Bluemail | 18/3/2020 | 17/6/2026 | The BlueMail application through 1.9.5.36 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Plixer Scrutinizer Netflow & Sflow Analyzer | 9/1/2020 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0.1.19899 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter. | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Plixer Scrutinizer Netflow & Sflow Analyzer | 9/1/2020 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allows remote attackers to inject arbitrary web script or HTML via the newUser parameter. NOTE: this might not be a vulnerability,… | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Plixer Scrutinizer Netflow & Sflow Analyzer | 9/1/2020 | 16/6/2026 | Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to cgi-bin/scrut_fa_exclusions.cgi, (2) getPermissionsAndPreferences… | |
| Modificada | Media (6.5) | 3.3% | 💥 Exploit | Plixer Scrutinizer Netflow & Sflow Analyzer | 9/1/2020 | 16/6/2026 | cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access. | |
| Modificada | Media (6.4) | 0.33% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Media (6.4) | 0.35% | — | Lenovo 510-15ikl FirmwareLenovo 510s-08ikl FirmwareLenovo Ideacentre 300-20ish FirmwareLenovo Ideacentre 300s-11ish Firmware+388 | 12/11/2019 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution. | |
| Modificada | Alta (7.2) | 2.2% | — | Schlix CMS | 24/10/2019 | 17/6/2026 | admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadvertently allowing a PHP file to be uploaded via Media Manager was an oversight, it still requires an admin permission. We think it's pretty rare for an administrator to… | |
| Modificada | Alta (7.5) | 1.1% | — | Netflix Dial Reference | 21/6/2019 | 17/6/2026 | Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019. | |
| Modificada | Alta (7.5) | 2.3% | — | Slixmpp Project Slixmpp | 4/2/2019 | 17/6/2026 | slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains an incorrect Access Control vulnerability in XEP-0223 plugin (Persistent Storage of Private Data via PubSub) options profile, used for the configuration of default access model that can result in all of the contacts of the victim can see… | |
| Modificada | Alta (7.8) | 0.40% | — | Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+55 | 24/1/2019 | 17/6/2026 | In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user. |