Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
–

56 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.34%—Infinitt Pacs System ManagerAI21/8/202517/6/2026
Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthorized access to system resources.
AnalizadaAlta (7.5)0.38%—Trellix Intrusion Prevention System Manager5/9/202417/6/2026
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
AnalizadaMedia (5.3)0.39%—Trellix Intrusion Prevention System Manager5/9/202417/6/2026
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
ModificadaMedia (4.4)0.15%—Avaya Aura System Manager8/8/202417/6/2026
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
AnalizadaMedia (6.7)0.19%—Avaya Aura System Manager8/8/202417/6/2026
A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
ModificadaAlta (7.2)0.58%—Trellix Intrusion Prevention System Manager4/11/202217/6/2026
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.
ModificadaAlta (7.5)1.3%—Netapp Ontap System Manager1/11/202117/6/2026
Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerability which could allow a remote attacker to cause a crash of the httpd server.
ModificadaMedia (5.5)0.22%—Netapp Ontap System Manager1/11/202117/6/2026
System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow a local attacker to discover plaintext iSCSI CHAP credentials.
ModificadaAlta (7.2)21%—LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+1915/2/202117/6/2026
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
ModificadaMedia (5.5)0.36%—Netapp Oncommand System Manager8/2/202117/6/2026
OnCommand System Manager 9.x versions prior to 9.3P20 and 9.4 prior to 9.4P3 are susceptible to a vulnerability that could allow HTTP clients to cache sensitive responses making them accessible to an attacker who has access to the system where the client runs.
ModificadaAlta (7.5)25%—Apache TomcatNetapp Element Plug-inNetapp Oncommand System ManagerDebian Linux+83/12/202017/6/2026
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead…
ModificadaMedia (4.8)8.3%—Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+1328/11/202017/6/2026
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely…
ModificadaMedia (6.5)2.9%—Avaya Aura System ManagerAvaya Weblm13/11/202017/6/2026
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
ModificadaAlta (7.5)87%—Apache TomcatDebian LinuxNetapp Oncommand System ManagerOpensuse Leap+1414/7/202025/8/2026
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
ModificadaAlta (7.5)64%—Apache TomcatDebian LinuxNetapp Oncommand System ManagerOpensuse Leap+1014/7/202025/8/2026
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
ModificadaAlta (7.5)27%—Apache TomcatCanonical Ubuntu LinuxOracle Mysql Enterprise MonitorOracle Siebel UI Framework+426/6/202017/6/2026
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
ModificadaMedia (6.1)6.3%—JqueryOracle Peoplesoft Enterprise PeopletoolsNetapp Active IQ Unified ManagerNetapp Cloud Backup+319/5/202017/6/2026
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
ModificadaMedia (6.1)99%—JqueryDrupalDebian LinuxFedoraproject Fedora+6629/4/202017/6/2026
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
AnalizadaMedia (6.1)85%⚠ Explotación activaJqueryDebian LinuxFedoraproject FedoraDrupal+4829/4/202017/6/2026
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
ModificadaMedia (5.4)0.63%—Netapp Oncommand System Manager24/3/202017/6/2026
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scripts into the SNMP Community Names label field.
AnalizadaCrítica (9.8)99%⚠ Explotación activaApache GeodeApache TomcatFedoraproject FedoraOracle Agile Engineering Data Management+1724/2/202025/8/2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising.…
ModificadaMedia (4.8)9.4%—Apache TomcatDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+1624/2/202017/6/2026
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly…
ModificadaMedia (4.8)8.9%—Apache TomcatApache TomeeOpensuse LeapNetapp Data Availability Services+1224/2/202025/8/2026
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy…
ModificadaAlta (7.2)3.5%—Netapp Oncommand System Manager31/1/202016/6/2026
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface.
ModificadaAlta (7.5)2.2%—Netapp Oncommand System Manager29/1/202016/6/2026
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.