Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 2.7% | — | Sangfor Operation AND Maintenance Security Management SystemAI | 3/8/2026 | 12/8/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack… | |
| Analizada | Baja (2.1) | 4.9% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation of the file /equipment/get_Information of the component HTTP POST Request Handler. Executing a manipulation of the argument fortEquipmentIp can lead to command… | |
| Analizada | Baja (2.1) | 3.1% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ip_and_port/port_validate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in command injection. The attack… | |
| Analizada | Media (5.5) | 4.3% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown function of the file /fort/audit/get_clip_img of the component HTTP POST Request Handler. Such manipulation of the argument frame/dirno leads to command injection. It is… | |
| Analizada | Media (5.5) | 0.58% | — | Sangfor Operation AND Maintenance Security Management System | 22/1/2026 | 17/6/2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/edit_pwd_mall. The manipulation of the argument flag results in weak password recovery. It is possible to launch the attack remotely. The… | |
| Analizada | Alta (7.4) | 7.1% | — | Sangfor Operation AND Maintenance Security Management System | 22/1/2026 | 17/6/2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os command injection. It… | |
| Analizada | Media (5.5) | 2.0% | 💥 Exploit | Sangfor Operation AND Maintenance Security Management System | 10/1/2026 | 17/6/2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out… | |
| Analizada | Media (5.5) | 6.1% | — | Sangfor Operation AND Maintenance Security Management System | 10/1/2026 | 17/6/2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be executed remotely. The… | |
| Analizada | Alta (8.9) | 6.9% | — | Sangfor Operation AND Maintenance Security Management System | 9/1/2026 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The… | |
| Analizada | Baja (2.1) | 5.1% | 💥 PoC | Sangfor Operation AND Maintenance Security Management System | 9/11/2025 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This manipulation of the argument loginUrl causes command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (8.8) | 0.57% | 💥 PoC | Qianxin Tianqing Endpoint Security Management System | 21/4/2025 | 17/6/2026 | The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities. | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | Esafenet Electronic Document Security Management System | 8/3/2019 | 17/6/2026 | ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request. | |
| Modificada | Alta (7.5) | 8.6% | — | HP Tippingpoint Security Management SystemHP Tippingpoint Virtual Security Management System | 27/4/2015 | 17/6/2026 | HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1 do not require authentication for JBoss RMI requests, which allows remote attackers to execute arbitrary code by (1) uploading this code within an archive or (2)… | |
| Modificada | Alta (7.5) | 5.5% | — | HP Security Management System | 6/3/2014 | 17/6/2026 | Unspecified vulnerability in HP Security Management System 3.3.0, 3.5.0 before patch 1, and 3.6.0 before patch 2 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Hirschelectronics Velocity Security Management System | 26/8/2009 | 16/6/2026 | Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Alta (7.5) | 1.6% | — | Mcafee Intrushield Security Management System | 11/7/2005 | 16/6/2026 | McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack. | |
| Modificada | Media (4.6) | 0.64% | — | Mcafee Intrushield Security Management System | 11/7/2005 | 16/6/2026 | McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to… | |
| Modificada | Baja (1.9) | 0.54% | — | Mcafee Intrushield Security Management System | 11/7/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp. |