Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 82% | — | Commvault Commcell | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Demo_ExecuteProcessOnGroup… | |
| Modificada | Alta (8.8) | 69% | — | Commvault Commcell | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DownloadCenterUploadHandler class.… | |
| Modificada | Alta (8.8) | 5.8% | — | Commvault Commcell | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue… | |
| Modificada | Crítica (9.8) | 5.4% | — | Commvault Commcell | 13/1/2022 | 17/6/2026 | This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService service. The issue results from the lack of proper validation prior to… | |
| Modificada | Media (6.5) | 0.96% | — | Jenkins Hashicorp Vault | 12/1/2022 | 17/6/2026 | Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed. | |
| Modificada | Media (4.2) | 0.49% | — | Encsecurity Datavault | 2/1/2022 | 17/6/2026 | ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation. | |
| Modificada | Alta (8.1) | 14% | 💥 PoC | Zendesk ENC DatavaultZendesk ENC VaultapiSandisk Secureaccess | 22/12/2021 | 17/6/2026 | ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names). | |
| Modificada | Media (4.9) | 1.4% | — | Hashicorp Vault | 17/12/2021 | 17/6/2026 | In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is… | |
| Modificada | Crítica (9.1) | 5.0% | — | Vault-cli Project Vault-cli | 16/12/2021 | 17/6/2026 | vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest of the contents of the secret as a… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Veritas Enterprise Vault | 6/12/2021 | 17/6/2026 | An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is… | |
| Modificada | Media (6.5) | 1.0% | — | Hashicorp Vault | 30/11/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6,… | |
| Modificada | Media (6.8) | 0.50% | — | Ionic Identity Vault | 19/11/2021 | 17/6/2026 | In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed. | |
| Modificada | Alta (8.1) | 0.78% | — | Hashicorp Vault | 11/10/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google… | |
| Modificada | Media (5.4) | 0.61% | — | Hashicorp Vault | 8/10/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4. | |
| Modificada | Media (6.7) | 0.53% | — | Ionic Identity Vault | 10/9/2021 | 17/6/2026 | In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication. | |
| Modificada | Media (5.3) | 1.0% | — | Hashicorp Vault | 31/8/2021 | 17/6/2026 | HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3. | |
| Modificada | Media (5.3) | 0.91% | — | Hashicorp Vault | 13/8/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases. | |
| Modificada | Media (4.4) | 0.27% | — | Hashicorp Vault | 13/8/2021 | 17/6/2026 | HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0. | |
| Modificada | Baja (2.7) | 0.76% | — | Oracle Database Vault | 21/7/2021 | 17/6/2026 | Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this… | |
| Modificada | Alta (7.5) | 1.1% | — | ATT Alienvault Ossim | 19/7/2021 | 17/6/2026 | A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events. |