Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)100%⚠ Explotación activa💥 ExploitApache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+544/10/201725/8/2026
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP…
AnalizadaAlta (8.1)100%⚠ Explotación activa💥 ExploitApache TomcatNetapp 7-mode Transition ToolNetapp Oncommand BalanceNetapp Oncommand Shift+1819/9/20176/8/2026
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed…
ModificadaAlta (8.8)87%💥 ExploitSupervisord SupervisorFedoraproject FedoraDebian LinuxRedhat Cloudforms23/8/201717/6/2026
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
ModificadaMedia (4.9)2.6%—EMC Data Protection Advisor9/7/201717/6/2026
EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged user may potentially exploit this vulnerability to access unauthorized information from the underlying OS server by supplying specially crafted strings in input parameters of the application.
ModificadaAlta (8.8)2.3%—EMC Data Protection Advisor9/7/201717/6/2026
EMC Data Protection Advisor prior to 6.4 contains multiple blind SQL injection vulnerabilities. A remote authenticated attacker may potentially exploit these vulnerabilities to gain information about the application by causing execution of arbitrary SQL commands.
ModificadaAlta (8.8)2.6%—Cisco Integrated Management Controller Supervisor20/4/201717/6/2026
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize user-supplied HTTP input. An attacker…
ModificadaMedia (5.4)0.93%—Cisco Integrated Management Controller Supervisor20/4/201717/6/2026
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this…
ModificadaMedia (5.4)0.97%—Cisco Integrated Management Controller Supervisor20/4/201717/6/2026
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not…
ModificadaAlta (8.8)4.2%—Cisco Integrated Management Controller Supervisor20/4/201717/6/2026
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of…
ModificadaAlta (7.5)11%—NettyRedhat Jboss Data GridRedhat Jboss Middleware Text-only AdvisoriesApache Cassandra13/4/201717/6/2026
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
ModificadaAlta (7)0.31%—Mcafee Security WebadvisorMcafee Cloud AVMcafee Security Scan Plus14/3/201717/6/2026
Malicious file execution vulnerability in Intel Security CloudAV (Beta) before 0.5.0.151.3 allows attackers to make the product momentarily vulnerable via executing preexisting specifically crafted malware during installation or uninstallation, but not during normal operation.
ModificadaAlta (7)0.31%—Mcafee Security WebadvisorMcafee Cloud AVMcafee Security Scan Plus14/3/201717/6/2026
Malicious file execution vulnerability in Intel Security WebAdvisor before 4.0.2, 4.0.1 and 3.7.2 allows attackers to make the product momentarily vulnerable via executing preexisting specifically crafted malware during installation or uninstallation, but not during normal operation.
ModificadaAlta (7)0.31%—Mcafee Security WebadvisorMcafee Cloud AVMcafee Security Scan Plus14/3/201717/6/2026
Malicious file execution vulnerability in Intel Security McAfee Security Scan+ (MSS+) before 3.11.266.3 allows attackers to make the product momentarily vulnerable via executing preexisting specifically crafted malware during installation or uninstallation, but not during normal operation.
ModificadaAlta (7.3)0.97%—Intel AdvisorCryptography FOR Intel Integrated Performance PrimitivesIntel Data Analytics Acceleration LibraryIntel Inspector+828/2/201717/6/2026
Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel…
ModificadaAlta (7.5)3.0%—Dell EMC Data Protection Advisor3/2/201717/6/2026
EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may potentially be exploited by malicious users to compromise the affected system.
ModificadaAlta (7.5)15%—Brocade Network Advisor14/1/201717/6/2026
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files including files with sensitive user information.
ModificadaAlta (7.5)15%—Brocade Network Advisor14/1/201717/6/2026
A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently delete the files.
ModificadaCrítica (9.8)13%—Brocade Network Advisor14/1/201717/6/2026
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.
ModificadaCrítica (9.8)7.1%—Broadcom Brocade Network Advisor14/1/201717/6/2026
A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.
ModificadaAlta (8.1)7.2%—HP Converged Infrastructure Solution Sizer SuiteHP Insight Management SizerHP Power AdvisorHP SAP Sizing Tool+1122/8/201617/6/2026
HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before…
AnalizadaCrítica (9.8)93%⚠ Explotación activa💥 ExploitApache AuroraApache ShiroRedhat FuseRedhat Jboss Middleware Text-only Advisories7/6/201617/6/2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
ModificadaAlta (7.5)2.2%—Carel Plantvisor Enhanced30/1/201617/6/2026
CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.
ModificadaMedia (6.8)2.2%—Cisco Integrated Management Controller Supervisor15/12/201517/6/2026
The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286.
ModificadaMedia (6.8)1.1%—EMC Sourceone Email Supervisor18/10/201517/6/2026
EMC SourceOne Email Supervisor before 7.2 uses hardcoded encryption keys, which makes it easier for attackers to obtain access by examining how a program's code conducts cryptographic operations.
ModificadaAlta (7.5)3.5%—EMC Sourceone Email Supervisor18/10/201517/6/2026
EMC SourceOne Email Supervisor before 7.2 does not properly employ random values for session IDs, which makes it easier for remote attackers to obtain access by guessing an ID.
Orbitaley — Vulnerabilidades