Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.52%—Lenovo Xclarity OrchestratorAI4/8/202624/8/2026
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
Pendiente de análisisAlta (7)0.11%—Lenovo Xclarity OrchestratorAI4/8/202624/8/2026
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation…
Pendiente de análisisBaja (1)0.13%—Lenovo Xclarity Essentials OnecliAI4/8/202624/8/2026
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Pendiente de análisisAlta (8.8)1.2%—Lenovo Xclarity Integrator FOR Windows Admin CenterAI16/7/202616/7/2026
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
AplazadaMedia (5.3)0.21%—Newclarity Dmca Protection BadgeAI31/12/202517/6/2026
Missing Authorization vulnerability in NewClarity DMCA Protection Badge dmca-badge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DMCA Protection Badge: from n/a through <= 2.2.0.
AplazadaAlta (8.7)0.25%—Lenovo Xclarity OrchestratorAI11/9/202517/6/2026
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) network segment may be able to manipulate the local device to create an alternate communication channel which could allow…
AnalizadaMedia (6.5)0.20%—Lenovo Xclarity Administrator13/9/202417/6/2026
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
AnalizadaMedia (4.3)0.34%—Lenovo Xclarity Administrator13/9/202417/6/2026
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
AplazadaMedia (6.5)0.44%—KubeclarityAI12/7/202417/6/2026
KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems. A time/boolean SQL Injection is present in the following resource `/api/applicationResources` via the following parameter `packageID`. As it can be seen in…
AplazadaMedia (6.5)0.46%—Lenovo Xclarity AdministratorAI5/4/202417/6/2026
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
ModificadaMedia (6.1)1.3%—Microsoft Clarity29/2/202417/6/2026
The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the edit_clarity_project_id() function. This makes it possible for unauthenticated attackers to change the project id and add malicious…
ModificadaMedia (5.4)0.49%—Broadcom Clarity9/11/202317/6/2026
Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function.
ModificadaAlta (7.5)0.50%—Lenovo Xclarity Administrator26/6/202317/6/2026
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
ModificadaMedia (6.5)0.49%—Lenovo Xclarity Administrator26/6/202317/6/2026
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
ModificadaMedia (6.5)0.49%—Lenovo Xclarity Administrator26/6/202317/6/2026
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
ModificadaAlta (7.2)1.3%—Lenovo Xclarity Administrator26/6/202317/6/2026
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
ModificadaAlta (8.1)0.55%—Lenovo Xclarity Administrator26/6/202317/6/2026
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.
ModificadaAlta (7.5)1.2%—Broadcom CA Clarity16/6/202217/6/2026
CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could allow a remote attacker to potentially view the contents of any file on the system.
ModificadaMedia (5.3)0.77%—Lenovo Xclarity Controller18/5/202217/6/2026
A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such as Microsoft Active Directory. An…
ModificadaMedia (5.4)1.6%—Microsoft Clarity19/11/202117/6/2026
There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page.
ModificadaMedia (4.9)0.48%—Lenovo Xclarity Controller13/4/202117/6/2026
An internal product security audit of Lenovo XClarity Controller (XCC) discovered that the XCC configuration backup/restore password may be written to an internal XCC log buffer if Lenovo XClarity Administrator (LXCA) is used to perform the backup/restore. The backup/restore password typically exists in this internal…
ModificadaMedia (4.9)0.56%—Lenovo Xclarity Orchestrator9/3/202117/6/2026
An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA. Affected logs are captured in the First Failure…
ModificadaMedia (4.9)0.56%—Lenovo Xclarity Orchestrator9/3/202117/6/2026
An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected logs are captured in the First Failure Data Capture (FFDC) service log. The FFDC service log is only…
ModificadaMedia (4.9)0.53%—Lenovo Xclarity Administrator10/2/202117/6/2026
An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while…
ModificadaMedia (6)0.31%—Lenovo Xclarity Administrator13/3/202017/6/2026
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when performing a Windows driver update. Affected logs are only accessible to…