Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.10% | — | Samsung ManagedprovisioningAI | 2/10/2026 | 2/10/2026 | Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications. | |
| Analizada | Crítica (9.9) | 1.0% | — | Microsoft Entra Provisioning Service | 7/8/2026 | 7/8/2026 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Entra Provisioning Service | 2/7/2026 | 8/7/2026 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Media (6.6) | 0.35% | — | SAP Operational Data Provisioning Data Replication APIAI | 9/6/2026 | 23/7/2026 | The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permitted SAP-internal applications and are being used by customer or third-party applications in ways that are not aligned with its intended usage. Which could lead to… | |
| Aplazada | Alta (8.6) | 1.8% | 💥 Exploit | Lantronix Provisioning ManagerAI | 22/7/2025 | 17/6/2026 | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed. | |
| Aplazada | Media (6.8) | 0.28% | — | Okta On-premises ProvisioningAI | 22/7/2025 | 17/6/2026 | Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by… | |
| Analizada | Media (5.3) | 0.55% | — | Oracle Fleet Patching AND Provisioning | 15/4/2025 | 17/6/2026 | Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.3-19.26. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and amp; Provisioning. Successful attacks of… | |
| Aplazada | Baja (3.5) | 0.60% | — | Mavenir SCE Application Provisioning PortalAI | 12/2/2025 | 17/6/2026 | A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an administrative user to access system files with the file permissions of the privileged system user running the application. | |
| Aplazada | Alta (8.8) | 0.39% | — | Mavenir SCE Application Provisioning PortalAI | 12/2/2025 | 17/6/2026 | An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls. | |
| Aplazada | Alta (7.1) | 0.32% | — | Realtyna ProvisioningAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna Provisioning realtyna-provisioning allows Reflected XSS.This issue affects Realtyna Provisioning: from n/a through <= 1.2.2. | |
| Aplazada | Media (5.3) | 0.38% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows… | |
| Aplazada | Alta (7.5) | 0.65% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet allows remote attackers to retrieve any file from the Kurmi web application installation folder, e.g., files such as the obfuscated… | |
| Aplazada | Media (4.9) | 0.85% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended files. Any file accessible to the Kurmi… | |
| Aplazada | Media (4.8) | 0.27% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15 allows remote attackers (authenticated as system administrators) to inject arbitrary web script or HTML via the COMPONENT_fields(htmlTitle)… | |
| Aplazada | Crítica (9.4) | 0.55% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be… | |
| Analizada | Media (5.4) | 0.16% | — | Intel Server Debug AND Provisioning Tool | 13/11/2024 | 17/6/2026 | Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.15% | — | Intel Server Debug AND Provisioning Tool | 13/11/2024 | 17/6/2026 | Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access. | |
| Analizada | Alta (7.3) | 0.27% | — | AMD Provisioning Console | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Analizada | Media (5.5) | 0.14% | — | Lenovo Dolby Vision Provisioning | 11/10/2024 | 17/6/2026 | A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by… | |
| Analizada | Media (4.8) | 0.24% | — | Citrix Provisioning | 10/7/2024 | 17/6/2026 | A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Server Debug AND Provisioning Tool | 11/8/2023 | 17/6/2026 | Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.16% | — | HPE Intelligent Provisioning | 18/7/2023 | 17/6/2026 | The vulnerability could be locally exploited to allow escalation of privilege. | |
| Modificada | Alta (7.5) | 0.54% | — | Intel Server Debug AND Provisioning Tool | 11/11/2022 | 17/6/2026 | Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… |