Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.43%—Devpi-serverAI14/9/202630/9/2026
devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary does not reject a missing identity and…
AnalizadaMedia (4.3)0.39%—Cdata API Server2/9/202517/6/2026
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the usage of MySQL…
AplazadaCrítica (9.8)8.1%—Cdata API ServerAIEclipse JettyAI5/4/202417/6/2026
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
ModificadaAlta (7.5)0.56%—Aveva PI Server18/1/202417/6/2026
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.
ModificadaMedia (5.3)0.50%—Aveva PI Server18/1/202417/6/2026
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message Subsystem of a PI Server to consume available memory resulting in throttled processing of new PI Data Archive events and a partial denial-of-service condition.
ModificadaMedia (6.5)1.3%—Osisoft PI ServerOsisoft PI SQL FOR AF26/5/201517/6/2026
OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.
ModificadaMedia (5)2.4%—Spumko Project Hapi Server Framework16/5/201417/6/2026
The hapi server framework 2.0.x and 2.1.x before 2.2.0 for Node.js allows remote attackers to cause a denial of service (file descriptor consumption and process crash) via unspecified vectors.
ModificadaMedia (6.4)0.67%—Osisoft PI Server1/10/200916/6/2026
PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.
ModificadaMedia (5)3.2%—Cyan Soft Cyanprintip BasicCyan Soft Cyanprintip Easy OPICyan Soft Cyanprintip ProfessionalCyan Soft Cyanprintip Standard+213/2/200816/6/2026
The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of service (daemon crash) via a connection that begins with (1) a "Send…
ModificadaAlta (7.5)4.9%—Cyan Soft Cyanprintip BasicCyan Soft Cyanprintip Easy OPICyan Soft Cyanprintip ProfessionalCyan Soft Cyanprintip Standard+213/2/200816/6/2026
Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; might allow remote attackers to execute…
ModificadaAlta (7.1)1.3%—Hitachi TPI Server Base15/7/200716/6/2026
Unspecified vulnerability in Hitachi TP1/Server Base before 03-05-/P, 05-00-x before 05-00-/G, 05-01-x before 05-01-/A, and 05-02-x before 05-02-/C on HP-UX 11.0 through 11i v3 allows attackers to cause a denial of service by sending certain data to a port.
ModificadaMedia (5)1.3%—Hitachi TPI LinkHitachi TPI Server Base26/1/200716/6/2026
Hitachi TP1/LiNK 05-00 through 05-03-/F, 03-04 through 03-06-/K, and 03-00 through 03-03-/H; and TP1/Server Base 05-00 through 05-00-/M, 03-01-E through 03-01-FD, 03-01 through 03-01-DB, and 05-03; allow attackers to cause a denial of service (process crash) via invalid data to an OpenTP1 port.
ModificadaMedia (5)1.6%—Hitachi Jp1-cm2-network Node ManagerHitachi Jp1-cm2-network Node Manager 250Hitachi JPI Automatic JOB Management System 2Hitachi JPI Performance Management+527/4/200616/6/2026
Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data.
ModificadaMedia (5)2.8%—Informs Picserver3/5/200116/6/2026
Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.