Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.43% | — | IngeniosoAI | 17/6/2026 | 30/9/2026 | Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions. | |
| Analizada | Alta (8.8) | 0.61% | — | Infoblox Nios | 12/2/2026 | 17/6/2026 | In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution. | |
| Analizada | Alta (7.7) | 0.28% | — | Infoblox Nios | 12/2/2026 | 17/6/2026 | In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism. | |
| Aplazada | Alta (7.5) | 0.31% | — | Oracle Sunos OmniosAI | 29/9/2025 | 17/6/2026 | An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets. | |
| Analizada | Crítica (9.1) | 0.35% | — | Infoblox Nios | 27/2/2025 | 17/6/2026 | Infoblox NIOS through 8.6.4 has Improper Access Control for Grids. | |
| Analizada | Crítica (9.8) | 0.46% | — | Infoblox Nios | 27/2/2025 | 17/6/2026 | Infoblox NIOS through 8.6.4 has Improper Authentication for Grids. | |
| Analizada | Crítica (9.8) | 0.44% | — | Infoblox Nios | 27/2/2025 | 17/6/2026 | Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation. | |
| Analizada | Crítica (9.8) | 0.41% | — | Infoblox Nios | 27/2/2025 | 17/6/2026 | Infoblox NIOS through 8.6.4 executes with more privileges than required. | |
| Modificada | Media (5.4) | 0.35% | — | Infoblox Nios | 9/1/2024 | 9/7/2026 | A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field. | |
| Modificada | Alta (8.8) | 0.73% | — | Infoblox Nios | 25/8/2023 | 17/6/2026 | Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access. | |
| Modificada | Media (5.5) | 0.32% | — | IllumosOmniosce OmniosOpenindianaJoyent Smartos+1 | 26/12/2022 | 17/6/2026 | An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is… | |
| Modificada | Media (4.3) | 0.68% | — | Inveniosoftware Invenio-drafts-resources | 6/12/2021 | 17/6/2026 | Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM.… | |
| Modificada | Media (6.5) | 0.86% | — | Infoblox Nios | 28/6/2021 | 17/6/2026 | Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564. | |
| Modificada | Crítica (9.8) | 1.4% | — | IllumosJoyent SmartosOmniosce Omnios | 26/10/2020 | 17/6/2026 | An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c. | |
| Modificada | Alta (8.2) | 0.60% | — | FreebsdOmniosce OmniosOpenindianaNetapp Clustered Data Ontap | 25/9/2020 | 17/6/2026 | bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP. | |
| Modificada | Alta (7.5) | 1.1% | — | Omniosce Omnios | 29/11/2019 | 17/6/2026 | illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences. | |
| Modificada | Media (6.1) | 0.93% | — | Inveniosoftware Invenio-app | 29/7/2019 | 17/6/2026 | invenio-app before 1.1.1 allows host header injection. | |
| Modificada | Media (5.4) | 0.68% | — | Inveniosoftware Invenio-communities | 29/7/2019 | 17/6/2026 | invenio-communities before 1.0.0a20 allows XSS. | |
| Modificada | Media (5.4) | 0.66% | — | Inveniosoftware Invenio-records | 29/7/2019 | 17/6/2026 | invenio-records before 1.2.2 allows XSS. | |
| Modificada | Media (6.1) | 0.90% | — | Inveniosoftware Invenio-previewer | 29/7/2019 | 17/6/2026 | invenio-previewer before 1.0.0a12 allows XSS. | |
| Modificada | Media (6.7) | 0.38% | — | Infoblox Nios | 17/6/2019 | 17/6/2026 | A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administrator to temporarily gain additional privileges on an affected device and perform actions within the super user scope. The vulnerability is due to a weakness in the… | |
| Modificada | Alta (7.5) | 1.2% | — | Dominios Europa Picrate | 13/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dominios Europa PICRATE (aka TAL RateMyPic) 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) voteid, and (3) vfiel parameters to (a) index.php, and via the (4) nick, (5) email, (6) city, (7) messen, and (8) message form field parameters to (b)… | |
| Modificada | Media (6.8) | 1.2% | — | Dominios Europa Picrate | 5/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dominios Europa PICRATE (aka TAL RateMyPic) 1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the (1) name (aka nick), (2) email, and (3) comment boxes; and via the (4) id… |