Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.45%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI21/9/202630/9/2026
A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the…
AplazadaBaja (2.1)0.46%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI21/9/202630/9/2026
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has…
Pendiente de análisisMedia (5.4)0.25%—Jenkins Gradle PluginAIGradleAIJetbrains DevelocityAI16/9/202618/9/2026
Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the…
Pendiente de análisisMedia (5.5)0.37%—DspaceAIApache VelocityAI2/9/20269/9/2026
DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, and 10-rc1 to before 10.0, a path traversal vulnerability is possible via the COAR Notify / LDN service in DSpace. The attacker MUST already have…
AplazadaCrítica (9.8)0.87%—Apache VelocityAIOpensagres XdocreportAI17/8/20269/9/2026
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
AplazadaCrítica (9.8)0.73%—Apache Velocity.jsAI13/8/202618/9/2026
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained…
AnalizadaCrítica (9.8)0.61%—Shepherdwind Velocity.js26/5/202624/7/2026
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it…
AnalizadaCrítica (9.8)0.23%—Hcltech Devops Velocity13/4/202630/9/2026
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7.
AplazadaMedia (6.8)0.27%—HCL VelocityAI7/2/202617/6/2026
Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7.
AplazadaMedia (4.4)0.24%—Fast Velocity MinifyAI25/10/202517/6/2026
The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
AplazadaAlta (7.1)0.34%—Gradle DevelocityAI26/1/202517/6/2026
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in affected vulnerable versions) does not include the projects…
AplazadaAlta (8.3)0.47%—Gradle DevelocityAI26/1/202517/6/2026
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and provides some protection against brute-force…
AnalizadaBaja (3.3)0.21%—Hcltech Devops VelocityIBM Urbancode Velocity20/1/202527/7/2026
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
AnalizadaAlta (7.5)0.36%—Hcltech Devops VelocityIBM Urbancode Velocity20/1/202527/7/2026
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
AnalizadaAlta (7.5)0.33%—Hcltech Devops VelocityIBM Urbancode Velocity20/1/202527/7/2026
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaAlta (7.8)0.23%—Ivanti Velocity License Server8/10/202417/6/2026
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
AplazadaAlta (7.5)0.71%—Komm.one CMSAIApache VelocityAI18/3/202417/6/2026
Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command.
ModificadaAlta (8.8)0.33%—Airspan Airvelocity 1500 Firmware16/8/202217/6/2026
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
ModificadaMedia (6.1)0.44%—Airspan Airvelocity 1500 Firmware16/8/202217/6/2026
Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP community field in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
ModificadaAlta (8.8)1.5%—Airspan Airvelocity 1500 Firmware16/8/202217/6/2026
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other AirVelocity and AirSpeed models.
ModificadaAlta (8.8)25%—Airspan Airvelocity 1500 Firmware16/8/202217/6/2026
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
ModificadaCrítica (9.1)0.73%—Airspan Airvelocity 1500 Firmware16/8/202217/6/2026
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP. This issue may affect other AirVelocity…
ModificadaMedia (6.8)0.31%—Airspan Airvelocity 1500 Firmware16/8/202217/6/2026
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
ModificadaMedia (6.5)0.97%—Airspan Airvelocity 1500 Firmware16/8/202217/6/2026
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity 1500 running software version 9.3.0.01249, were still present in 15.18.00.2511,…
ModificadaCrítica (9.1)20%—In4velocity In4suite ERP1/6/202117/6/2026
SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.