Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 1.8% | — | Lantronix Provisioning ManagerAI | 22/7/2025 | 17/6/2026 | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed. | |
| Modificada | Media (4.4) | 1.2% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning… | |
| Modificada | Crítica (9.8) | 3.0% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2… | |
| Modificada | Crítica (9.8) | 1.3% | — | Akkadianlabs OVA ApplianceAkkadianlabs Provisioning Manager | 22/7/2021 | 17/6/2026 | Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later). | |
| Modificada | Alta (8.8) | 1.3% | — | Akkadianlabs Akkadian Provisioning Manager | 1/7/2021 | 17/6/2026 | An issue exists within the SSH console of Akkadian Provisioning Manager 4.50.02 which allows a low-level privileged user to escape the web configuration file editor and escalate privileges. | |
| Modificada | Alta (7.5) | 6.8% | — | Akkadianlabs Akkadian Provisioning Manager | 1/7/2021 | 17/6/2026 | An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories. | |
| Modificada | Alta (8.8) | 1.2% | — | SAP Software Provisioning Manager | 9/2/2021 | 17/6/2026 | SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade. | |
| Modificada | Crítica (9.8) | 12% | — | HP Moonshot Provisioning Manager | 9/2/2021 | 17/6/2026 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be… | |
| Modificada | Crítica (9.8) | 7.9% | — | HP Moonshot Provisioning Manager | 9/2/2021 | 17/6/2026 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulnerability could be… | |
| Modificada | Media (5.5) | 0.73% | — | HP Moonshot Provisioning ManagerCanonical Ubuntu Linux | 6/8/2018 | 17/6/2026 | A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. | |
| Modificada | Crítica (9.8) | 3.1% | — | HP Moonshot Provisioning Manager | 6/8/2018 | 17/6/2026 | A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. | |
| Modificada | Crítica (9.1) | 4.1% | — | HP Moonshot Provisioning Manager Appliance | 15/2/2018 | 17/6/2026 | A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. | |
| Modificada | Crítica (9.8) | 18% | — | HP Moonshot Provisioning Manager Appliance | 15/2/2018 | 17/6/2026 | A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. | |
| Modificada | Crítica (9.8) | 18% | — | HP Moonshot Provisioning Manager Appliance | 15/2/2018 | 17/6/2026 | A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found. | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+7 | 29/4/2013 | 16/6/2026 | The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Networking Manager (ANM), Prime Network Control System, Prime LAN Management Solution (LMS), Prime Collaboration, Unified Provisioning Manager, Network Services Manager, Prime… | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+6 | 19/2/2013 | 16/6/2026 | The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services… | |
| Modificada | Alta (7.5) | 1.8% | — | IBM Tivoli Provisioning Manager Express FOR Software Distribution | 6/3/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterAgentKey function in the SoapServlet servlet, (2) the User.updateUserValue function in the… | |
| Modificada | Alta (9.3) | 37% | — | IBM Tivoli Provisioning Manager Express FOR Software Distribution | 6/3/2012 | 16/6/2026 | Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allows remote attackers to execute arbitrary code via vectors related to an Asset Information file. | |
| Modificada | Alta (7.5) | 3.2% | — | IBM Tivoli Provisioning Manager OS Deployment | 28/10/2010 | 16/6/2026 | The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft… | |
| Modificada | Alta (10) | 13% | — | Ciscoworks Common ServicesCiscoworks Health AND Utilization MonitorCiscoworks LAN Management SolutionCiscoworks QOS Policy Manager+6 | 21/5/2009 | 16/6/2026 | Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows… | |
| Modificada | Alta (8.5) | 2.1% | — | IBM Tivoli Provisioning Manager | 19/12/2008 | 16/6/2026 | IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by… | |
| Modificada | Alta (10) | 8.4% | — | IBM Tivoli Provisioning Manager OS Deployment | 23/1/2008 | 16/6/2026 | Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port… | |
| Modificada | Media (4.3) | 1.0% | — | IBM Tivoli Provisioning Manager Express | 17/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Provisioning Manager Express allow remote attackers to inject arbitrary web script or HTML via the (1) "assess modification," (2) user-id, and other unspecified fields to the /tpmx URI; or (3) involving unspecified vectors related to "error processing." | |
| Modificada | Media (5) | 1.2% | — | IBM Tivoli Provisioning Manager Express | 17/12/2007 | 16/6/2026 | IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames. | |
| Modificada | Alta (7.5) | 2.2% | — | IBM Tivoli Provisioning Manager OS Deployment | 18/7/2007 | 16/6/2026 | The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of service (rembo.exe crash and multiple service outage) via a read (RRQ) request with an invalid blksize (blocksize), which triggers a divide-by-zero error. |