Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.43%—Netscout Ngeniusone25/4/202517/6/2026
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.
AnalizadaCrítica (9.8)0.44%—Netscout Ngeniusone25/4/202517/6/2026
NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.
AnalizadaMedia (6.1)0.25%—Netscout Ngeniusone25/4/202517/6/2026
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.
AnalizadaAlta (7.5)0.41%—Netscout Ngeniusone25/4/202517/6/2026
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.
AnalizadaAlta (7.5)0.38%—Netscout Ngeniusone25/4/202517/6/2026
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
AnalizadaAlta (7.1)0.22%—Netscout Ngeniusone25/4/202517/6/2026
NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.
AplazadaCrítica (9.8)0.44%—Netscout NgeniusoneAI25/4/202517/6/2026
NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration.
AnalizadaMedia (6.5)0.35%—Netscout Ngeniusone25/4/202517/6/2026
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.
ModificadaMedia (6.1)0.54%—Netscout Ngeniusone9/1/20249/7/2026
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).
ModificadaCrítica (9.8)1.1%—Netscout Ngeniusone9/1/20249/7/2026
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.
ModificadaMedia (5.4)0.51%—Netscout Ngeniusone9/1/20249/7/2026
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.
ModificadaMedia (5.4)0.39%—Netscout Ngeniusone7/12/202317/6/2026
NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated user.
ModificadaMedia (5.4)0.39%—Netscout Ngeniusone7/12/202317/6/2026
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4).
ModificadaMedia (5.4)0.39%—Netscout Ngeniusone7/12/202317/6/2026
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4).
ModificadaMedia (6.1)0.41%—Netscout Ngeniusone7/12/202317/6/2026
NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability.
ModificadaMedia (5.4)0.39%—Netscout Ngeniusone7/12/202317/6/2026
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4).
ModificadaMedia (5.4)0.39%—Netscout Ngeniusone7/12/202317/6/2026
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4).
ModificadaBaja (3.5)0.32%—Netscout Ngeniusone27/1/202317/6/2026
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required…
ModificadaBaja (3.1)0.28%—Netscout Ngeniusone27/1/202317/6/2026
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required…
ModificadaAlta (8.8)0.73%—Netscout Ngeniusone27/1/202317/6/2026
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.
ModificadaMedia (6.1)0.35%—Netscout Ngeniusone27/1/202317/6/2026
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 6 of 6.
ModificadaMedia (6.1)0.35%—Netscout Ngeniusone27/1/202317/6/2026
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 5 of 6.
ModificadaMedia (6.1)0.35%—Netscout Ngeniusone27/1/202317/6/2026
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 4 of 6.
ModificadaMedia (6.1)0.35%—Netscout Ngeniusone27/1/202317/6/2026
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 3 of 6.
ModificadaMedia (6.1)0.35%—Netscout Ngeniusone27/1/202317/6/2026
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 2 of 6.