Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.3)0.22%—Environment-modulesAI15/9/202621/9/2026
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is…
AplazadaCrítica (9.3)3.2%—Proxmox Virtual EnvironmentAIProxmox Libpve-access-controlAI1/9/20268/9/2026
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login…
AplazadaMedia (5.5)0.41%—Shenzhen Gongji Technology Xbrother Dynamic Environment Monitoring SystemAI24/8/202624/8/2026
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to…
AplazadaMedia (6.5)0.34%—Proxmox Virtual EnvironmentAIProxmox Qemu-serverAI17/7/202617/7/2026
Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.
AplazadaAlta (7.2)0.39%—Proxmox Virtual EnvironmentAIProxmox Pve-managerAIProxmox Qemu-serverAIProxmox Pve-containerAI17/7/202617/7/2026
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call…
AplazadaMedia (6.1)0.25%—Proxmox Virtual EnvironmentAI17/7/202617/7/2026
A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
AplazadaAlta (8.6)0.19%—Yeoman EnvironmentAI16/6/202617/6/2026
Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled…
AnalizadaMedia (6.6)0.24%—Oracle Cloud Native Environment Command Line Interface6/5/202617/6/2026
Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interface product via a…
AplazadaMedia (5.5)0.47%—Acrel Environmental Monitoring Cloud PlatformAI22/3/202617/6/2026
A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this…
AnalizadaAlta (7.8)0.66%—Dell Unity Operating Environment30/1/202617/6/2026
Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
AnalizadaAlta (7.8)0.66%—Dell Unity Operating Environment30/1/202617/6/2026
Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
AplazadaAlta (7.3)0.13%—Xilinx RUN Time EnvironmentAI24/11/202517/6/2026
A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced extensible interface (AXI), potentially resulting in loss of confidentiality, integrity, and/or availability.
AnalizadaAlta (7.8)0.50%—Dell Unity Operating Environment30/10/202517/6/2026
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
AnalizadaAlta (7.8)0.57%—Dell Unity Operating Environment30/10/202517/6/2026
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.
AnalizadaAlta (7.8)0.69%—Dell Unity Operating Environment30/10/202517/6/2026
Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. This vulnerability…
AnalizadaAlta (7.8)0.57%—Dell Unity Operating Environment30/10/202517/6/2026
Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.
AnalizadaAlta (7.8)0.57%—Dell Unity Operating Environment30/10/202517/6/2026
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.
AnalizadaAlta (7.8)0.50%—Dell Unity Operating Environment30/10/202530/9/2026
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
AnalizadaMedia (5.4)0.29%—Proxmox Virtual Environment9/9/202517/6/2026
A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side…
AnalizadaMedia (5.4)0.29%—Proxmox Virtual Environment9/9/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input. The payload is rendered unsafely in the Web UI and executed when viewed by other users, potentially leading to session…
AnalizadaMedia (5.4)0.34%—Proxmox Virtual Environment9/9/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated user to inject malicious input. The input is stored and executed in the context of other users' browsers when they view the affected…
AplazadaBaja (2.1)0.34%—Acrel Environmental Monitoring Cloud PlatformAI18/8/202517/6/2026
A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (5.5)0.24%—Advanced Intrusion Detection Environment Project Advanced Intrusion Detection Environment14/8/202517/6/2026
AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a…
ModificadaMedia (5.5)0.23%—Advanced Intrusion Detection Environment Project Advanced Intrusion Detection Environment14/8/202517/6/2026
AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. An attacker can craft a malicious filename by including terminal escape sequences to hide the addition or removal of the file from the report and/or tamper with the log…
AnalizadaAlta (7.8)0.47%—Dell Unity Operating Environment4/8/202517/6/2026
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.