Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.65%—Apple Server ManagerAI13/8/202517/6/2026
UnForm Server Manager versions prior to 10.1.12 expose an unauthenticated file read vulnerability via its log file analysis interface. The flaw resides in the arc endpoint, which accepts a fl parameter to specify the log file to be opened. Due to insufficient input validation and lack of path sanitization, attackers…
ModificadaMedia (5.9)0.73%—Redhat Enterprise VirtualizationRedhat VdsclientRedhat Virtual Desktop Server Manager13/11/201917/6/2026
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
ModificadaMedia (5.5)0.42%—Redhat Virtual Desktop Server ManagerRedhat Enterprise VirtualizationRedhat Storage4/11/201916/6/2026
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
ModificadaAlta (8.8)0.58%—Tibco Datasynapse Gridserver Manager13/11/201817/6/2026
The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an unauthenticated user to perform cross-site request forgery (CSRF). Affected releases are TIBCO Software Inc. TIBCO DataSynapse GridServer Manager: versions…
ModificadaMedia (5.4)0.68%—Tibco Datasynapse Gridserver Manager1/5/201817/6/2026
The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS). In addition, an authenticated user could be a victim of a cross-site request forgery (CSRF) attack.…
ModificadaMedia (6.8)0.18%—Tibco Datasynapse Gridserver Manager1/5/201817/6/2026
The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encryption mechanisms and the use of weak ciphers. A malicious actor could theoretically compromise the traffic between any…
ModificadaMedia (4.3)0.94%—EMC Smarts IP ManagerEMC Smarts Mpls ManagerEMC Smarts Network Protocol ManagerEMC Smarts Server Manager+228/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in EMC Smarts IP Manager, Smarts Service Assurance Manager, Smarts Server Manager, Smarts VoIP Availability Manager, Smarts Network Protocol Manager, and Smarts MPLS Manager before 9.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaAlta (10)9.9%—Landesk Management SuiteLandesk Security SuiteLandesk Server Manager18/9/200816/6/2026
Multiple buffer overflows in the QIP Server Service (aka qipsrvr.exe) in LANDesk Management Suite, Security Suite, and Server Manager 8.8 and earlier allow remote attackers to execute arbitrary code via a crafted heal request, related to the StringToMap and StringSize arguments.
ModificadaMedia (6.8)2.2%—Apple Server Manager13/3/200716/6/2026
Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows remote attackers to bypass authentication and modify system configuration.
ModificadaMedia (5)1.6%—Hitachi Jp1-cm2-network Node ManagerHitachi Jp1-cm2-network Node Manager 250Hitachi JPI Automatic JOB Management System 2Hitachi JPI Performance Management+527/4/200616/6/2026
Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data.