Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 1.5% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. | |
| Pendiente de análisis | Crítica (9.8) | 0.65% | — | Solarwinds Observability Self-hostedAI | 22/9/2026 | 24/9/2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. | |
| Analizada | Alta (8.1) | 0.42% | — | Solarwinds Observability Self-hosted | 26/3/2026 | 17/6/2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Alta (8.7) | 0.45% | — | Solarwinds Observability Self-hosted | 26/3/2026 | 17/6/2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Media (4.4) | 0.23% | — | Solarwinds Observability Self-hosted | 18/11/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required. | |
| Analizada | Media (5.4) | 0.28% | — | Solarwinds Observability Self-hosted | 18/11/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account. | |
| Analizada | Media (4.6) | 0.24% | — | Solarwinds Observability Self-hosted | 21/10/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege account. | |
| Analizada | Alta (7.8) | 0.29% | — | Solarwinds Observability Self-hosted | 24/7/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from a low-level account… | |
| Analizada | Media (4.3) | 0.21% | — | Solarwinds Observability Self-hosted | 10/6/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required. | |
| Analizada | Media (4.8) | 0.19% | — | Solarwinds Observability Self-hosted | 10/6/2025 | 17/6/2026 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required. |