Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.65% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | A vulnerability in the secure configuration of authentication and management services in Brocade Fabric OS before Fabric OS 9.2.1c2 could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands as root using “supportsave”, “seccertmgmt”, “configupload” command. | |
| Analizada | Media (6) | 0.16% | — | Broadcom Fabric Operating System | 3/2/2026 | 17/6/2026 | Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated attacker to reveal command line passwords using commands that may expose higher privilege sensitive information by a lower privileged user. | |
| Analizada | Alta (7.8) | 0.66% | — | Dell Unity Operating Environment | 30/1/2026 | 17/6/2026 | Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Alta (7.8) | 0.66% | — | Dell Unity Operating Environment | 30/1/2026 | 17/6/2026 | Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. | |
| Analizada | Baja (2.1) | 4.9% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation of the file /equipment/get_Information of the component HTTP POST Request Handler. Executing a manipulation of the argument fortEquipmentIp can lead to command… | |
| Analizada | Baja (2.1) | 3.1% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ip_and_port/port_validate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in command injection. The attack… | |
| Analizada | Media (5.5) | 4.3% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown function of the file /fort/audit/get_clip_img of the component HTTP POST Request Handler. Such manipulation of the argument frame/dirno leads to command injection. It is… | |
| Analizada | Media (5.5) | 0.58% | — | Sangfor Operation AND Maintenance Security Management System | 22/1/2026 | 17/6/2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/edit_pwd_mall. The manipulation of the argument flag results in weak password recovery. It is possible to launch the attack remotely. The… | |
| Analizada | Alta (7.4) | 7.1% | — | Sangfor Operation AND Maintenance Security Management System | 22/1/2026 | 17/6/2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os command injection. It… | |
| Analizada | Media (5.3) | 0.35% | — | Control-plane Flux Operator | 21/1/2026 | 17/6/2026 | The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in version 0.36.0 and prior to version 0.40.0, a privilege escalation vulnerability exists in the Flux Operator Web UI authentication code that allows an attacker to bypass… | |
| Modificada | Crítica (9.3) | 0.19% | — | External-secrets External Secrets Operator | 21/1/2026 | 15/7/2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to… | |
| Analizada | Alta (8.6) | 0.34% | — | Oracle Hospitality Opera 5 | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5.6.27.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Analizada | Media (6.1) | 0.22% | — | Oracle Hospitality Opera 5 | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.23, 5.6.25.17, 5.6.26.10 and 5.6.27.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Aplazada | Alta (8.4) | 0.14% | — | IBM Licensing OperatorAI | 20/1/2026 | 17/6/2026 | IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image. | |
| Analizada | Media (5.5) | 2.0% | 💥 Exploit | Sangfor Operation AND Maintenance Security Management System | 10/1/2026 | 17/6/2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out… | |
| Analizada | Media (5.5) | 6.1% | — | Sangfor Operation AND Maintenance Security Management System | 10/1/2026 | 17/6/2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be executed remotely. The… | |
| Analizada | Alta (8.9) | 6.9% | — | Sangfor Operation AND Maintenance Security Management System | 9/1/2026 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The… | |
| Analizada | Alta (8.9) | 6.1% | — | Sangfor Operation AND Maintenance Management System | 9/1/2026 | 17/6/2026 | A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results in os command injection. The attack may… | |
| Analizada | Alta (7.4) | 5.7% | — | Sangfor Operation AND Maintenance Management System | 9/1/2026 | 17/6/2026 | A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.2) | 1.5% | — | Dell Data Domain Operating System | 9/1/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special… | |
| Analizada | Media (4.9) | 0.32% | — | Dell Data Domain Operating System | 9/1/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain an Exposure of Sensitive Information to an… | |
| Analizada | Media (6.7) | 0.56% | — | Dell Data Domain Operating System | 9/1/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS2023 release versions 7.10.1.0 through 7.10.1.70, contain an Improper Neutralization of Special Elements… | |
| Analizada | Media (4.4) | 0.15% | — | Dell Data Domain Operating System | 9/1/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 release version 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, LTS 2023 release versions 7.10.1.0 through 7.10.1.70, contain a Heap-based Buffer Overflow vulnerability. A… | |
| Aplazada | Media (6.5) | 0.18% | — | Openai OperatorAI | 16/12/2025 | 17/6/2026 | Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows an on-path attacker to read database contents, potentially including credentials | |
| Aplazada | Alta (8.7) | 0.20% | — | Redhat Runtimes-inventory-rhel8-operatorAI | 15/12/2025 | 22/8/2026 | A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user… |