Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.78%—Opentelemetry Propagator JaegerAI8/7/202610/7/2026
OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed percent-encoded…
AplazadaMedia (4.3)0.39%—Tempo OperatorAIJaeger UIAI2/4/20258/9/2026
A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user…
ModificadaMedia (5.4)1.1%—Jaegertracing Jaeger UI17/7/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via the KeyValuesTable component.
ModificadaCrítica (9.4)0.66%—ABB MybuildingsMybusch-jaeger27/9/202117/6/2026
The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/his my.busch-jaeger.de or mybuildings.abb.com profile. A successful attacker can observe and control a ControlTouch remotely under very…
ModificadaMedia (5.5)0.43%—Linuxfoundation Jaeger19/6/202017/6/2026
Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. This flaw allows an attacker with access to the container's log file to discover the Kafka credentials.
ModificadaMedia (5.5)0.23%—ABB Tg/s3.2 FirmwareBusch-jaeger 6186/11 Firmware22/4/202017/6/2026
The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed).
ModificadaCrítica (9.1)1.3%—ABB Tg/s3.2 FirmwareBusch-jaeger 6186/11 Firmware22/4/202017/6/2026
Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to access data marked as restricted, such as viewing or editing user profiles and application settings.
ModificadaMedia (5.5)0.30%—ABB Tg/s3.2 FirmwareBusch-jaeger 6186/11 Firmware22/4/202017/6/2026
The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other configuration's credentials in plaintext.
ModificadaCrítica (9.8)1.4%—ABB Tg/s3.2 FirmwareBusch-jaeger 6186/11 Firmware22/4/202017/6/2026
The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (URL) , violating the access-control (ACL) rules. This issue allows obtaining sensitive information…
ModificadaMedia (4.3)1.2%—Kristof DE Jaeger Display Suite25/6/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label.
ModificadaMedia (6)1.8%—Kristof DE Jaeger Bundle Copy14/8/201216/6/2026
The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.
ModificadaMedia (5)1.2%—Kristof DE Jaeger Commentreference31/12/200916/6/2026
The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to bypass intended access restrictions and read comments by using the autocomplete path.