Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 1.0% | — | Redhat Jboss Operations Network | 3/10/2019 | 17/6/2026 | It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can… | |
| Modificada | Crítica (9.8) | 18% | — | Haxx CurlFedoraproject FedoraOpensuse LeapNetapp Cloud Backup+13 | 16/9/2019 | 17/6/2026 | Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. | |
| Modificada | Crítica (9.8) | 7.5% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Steelstore+8 | 16/9/2019 | 17/6/2026 | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. | |
| Modificada | Alta (7.5) | 5.4% | — | PythonFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+6 | 6/9/2019 | 17/6/2026 | An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could… | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 5/9/2019 | 17/6/2026 | IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operations for Waternamics V5.1.0 - V5.2.1.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user… | |
| Modificada | Media (6.2) | 0.39% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 20/8/2019 | 17/6/2026 | IBM Intelligent Operations Center V5.1.0 through V5.2.0 could disclose detailed error messages, revealing sensitive information that could aid in further attacks against the system. IBM X-Force ID: 162738. | |
| Modificada | Alta (8.2) | 2.4% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 20/8/2019 | 17/6/2026 | IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162737. | |
| Modificada | Alta (7.5) | 1.1% | — | Pivotal Software Application ServicePivotal Software Cloud Foundry UAAPivotal Software Operations Manager | 5/8/2019 | 17/6/2026 | Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess. | |
| Modificada | Alta (7.2) | 24% | — | Redislabs RedisRedhat OpenstackRedhat Enterprise LinuxRedhat Enterprise Linux EUS+5 | 11/7/2019 | 17/6/2026 | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a… | |
| Modificada | Alta (7.2) | 26% | — | Redislabs RedisRedhat OpenstackRedhat Software CollectionsRedhat Enterprise Linux+6 | 11/7/2019 | 17/6/2026 | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond… | |
| Modificada | Media (5.3) | 1.6% | — | IBM Spectrum Protect Operations Center | 2/7/2019 | 17/6/2026 | IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to obtain sensitive information, caused by an error message containing a stack trace. By creating an error with a stack trace, an attacker could exploit this vulnerability to potentially obtain details on the Operations Center… | |
| Modificada | Alta (7.8) | 0.53% | — | IBM Spectrum Protect Operations Center | 2/7/2019 | 17/6/2026 | IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on the system, caused by loading a specially crafted library loaded by the dsmqsan module. By setting up such a library, a local attacker could exploit this vulnerability to gain root privileges on the… | |
| Modificada | Crítica (9.8) | 7.0% | — | IBM Spectrum Protect Operations Center | 2/7/2019 | 17/6/2026 | IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and… | |
| Modificada | Media (5.4) | 0.66% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157015. | |
| Modificada | Alta (8.8) | 1.4% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM X-Force ID: 157014. | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013. | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012. | |
| Modificada | Alta (8.8) | 2.0% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 7/6/2019 | 17/6/2026 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 could allow an authenciated user to create arbitrary users which could cause ID management issues and result in code execution. IBM X-Force ID: 157011. | |
| Modificada | Media (5.4) | 0.65% | — | Pivotal Software Operations Manager | 6/6/2019 | 17/6/2026 | The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have… | |
| Modificada | Alta (8.8) | 1.8% | — | Microfocus Network AutomationMicrofocus Network Operations Management | 29/4/2019 | 17/6/2026 | A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions. The vulnerability could be remotely exploited to Remote Code Execution. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Crítica (9.8) | 1.8% | — | Cloudbees Jenkins Operations Center | 19/4/2019 | 17/6/2026 | CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page. | |
| Modificada | Media (5.4) | 0.85% | — | Pivotal Software Operations Manager | 7/3/2019 | 17/6/2026 | Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could… | |
| Modificada | Crítica (9.8) | 3.5% | — | SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+5 | 20/2/2019 | 17/6/2026 | SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. | |
| Modificada | Alta (7.8) | 1.8% | — | SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+5 | 6/2/2019 | 17/6/2026 | SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. |