Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.3) | 0.22% | — | Primekey Ejbca | 25/8/2021 | 17/6/2026 | An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Access was disabled. With this setting disabled it's not possible to… | |
| Modificada | Media (5.4) | 0.36% | — | Primekey Ejbca | 25/8/2021 | 17/6/2026 | An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client… | |
| Modificada | Baja (2.7) | 0.41% | — | Primekey Ejbca | 25/8/2021 | 17/6/2026 | An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the… | |
| Modificada | Baja (2.2) | 0.54% | — | Primekey Ejbca | 25/8/2021 | 17/6/2026 | An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While hidden from direct view, checking the page source would reveal the secret. | |
| Modificada | Alta (8.8) | 2.1% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 22/5/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to insufficient validation of user-supplied input to the… | |
| Modificada | Baja (3.4) | 0.21% | — | Cisco Evolved Programmable Network ManagerCisco Identity Services EngineCisco Prime Infrastructure | 22/5/2021 | 17/6/2026 | A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system. This vulnerability is due to improper… | |
| Modificada | Alta (8.8) | 2.7% | — | Cisco Prime License ManagerCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence ServiceCisco Unity Connection | 8/4/2021 | 17/6/2026 | A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to… | |
| Modificada | Alta (7.5) | 1.5% | — | Fujixerox Docucentre-vii C7773 FirmwareFujixerox Docucentre-vii C6673 FirmwareFujixerox Docucentre-vii C5573 FirmwareFujixerox Docucentre-vii C4473 Firmware+71 | 25/3/2021 | 17/6/2026 | Fuji Xerox multifunction devices and printers (DocuCentre-VII C7773/C6673/C5573/C4473/C3373/C3372/C2273, DocuCentre-VII C7788/C6688/C5588, ApeosPort-VII C7773/C6673/C5573/C4473/C3373/C3372 C2273, ApeosPort-VII C7788/C6688/C5588, ApeosPort C7070/C6570/C5570/C4570/C3570/C3070/C7070G/C6570G/C5570G/C4570G/C3570G/C3070G,… | |
| Modificada | Media (6.5) | 0.91% | — | Cisco Emergency ResponderCisco Prime License ManagerCisco Unified Communications ManagerCisco Unified Communications Manager IM & Presence Service+1 | 13/1/2021 | 17/6/2026 | A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an… | |
| Modificada | Media (4.3) | 0.36% | — | Primekey Ejbca | 19/11/2020 | 17/6/2026 | An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the restriction of client certificates (for the RA, not the end user) to a limited set of allowed CAs, thus restricting the… | |
| Modificada | Alta (7.5) | 1.2% | — | Intel Quartus Prime | 12/11/2020 | 17/6/2026 | Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Media (5.5) | 0.27% | — | Intel Quartus Prime | 12/11/2020 | 17/6/2026 | Uncaught exception in the Intel(R) 50GbE IP Core for Intel(R) Quartus Prime before version 20.2 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.8) | 0.37% | — | Intel Quartus PrimeIntel Stratix 10 Fpga Firmware | 12/11/2020 | 17/6/2026 | Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.1 may allow an unauthenticated user to potentially enable escalation of privilege and/or information disclosure via physical access. | |
| Modificada | Media (6.8) | 0.36% | — | Intel Quartus Prime PROIntel Stratix 10 Fpga Firmware | 12/11/2020 | 17/6/2026 | Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.2 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Alta (7.3) | 0.49% | — | Primekey Ejbca | 11/9/2020 | 17/6/2026 | An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certificate. This vulnerability can only affect a system that has EST configured, uses client certificates to authenticate enrollment, and has… | |
| Modificada | Crítica (9.8) | 3.1% | — | Cisco Prime License Manager | 16/7/2020 | 17/6/2026 | A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient validation of user input on the web management interface. An attacker could exploit… | |
| Modificada | Media (5.4) | 1.1% | — | Cisco Prime Infrastructure | 3/6/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.5) | 1.5% | — | Cisco Prime Network Registrar | 22/5/2020 | 17/6/2026 | A vulnerability in the DHCP server of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of incoming DHCP traffic. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.2) | 0.94% | — | Cisco Prime Collaboration Provisioning | 22/5/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates user input for specific… | |
| Modificada | Media (6.5) | 1.1% | — | Primekey Ejbca | 8/4/2020 | 17/6/2026 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of other bugs. This follow-on exploitation can lead to privilege escalation and remote code execution. (This is exploitable only when at least… | |
| Modificada | Crítica (9.8) | 1.3% | — | Primekey Ejbca | 8/4/2020 | 17/6/2026 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects to be deserialized. | |
| Modificada | Alta (7.2) | 0.58% | — | Primekey Ejbca | 8/4/2020 | 17/6/2026 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save uploaded test certificates to the server. An attacker who has gained access to the CA UI could… | |
| Modificada | Media (5.3) | 0.86% | — | Primekey Ejbca | 8/4/2020 | 17/6/2026 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by modifying the URI string from a client. (EJBCA's internal access control… | |
| Modificada | Alta (8.8) | 0.45% | — | Primekey Ejbca | 8/4/2020 | 17/6/2026 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI. | |
| Modificada | Media (6.1) | 0.39% | — | Primekey Ejbca | 8/4/2020 | 17/6/2026 | An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets. |