Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.56%—Microsoft Azure Virtual Machines20/8/202626/8/2026
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
AplazadaBaja (2)0.12%—Suse Virtual Machine Driver PackAI14/7/202629/9/2026
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registry to affect the integrity of the driver. We're not aware of a feasible way to exploit this currently. This issue affects Virtual Machine…
AnalizadaAlta (7.5)0.41%—Oracle Java Virtual Machine21/4/202617/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.30 and 21.3-21.21. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in…
AnalizadaCrítica (10)13%⚠ Explotación activaDell Recoverpoint FOR Virtual Machines17/2/202617/6/2026
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying…
AplazadaAlta (7.5)0.47%—TON Virtual MachineAI13/2/202617/6/2026
A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the RUNVM instruction logic (VmState::run_child_vm), which is responsible for initializing child virtual machines. The operation moves critical resources (specifically libraries and log) from the parent…
AplazadaAlta (7.5)0.63%—TON Virtual MachineAI13/2/202617/6/2026
A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems from the improper handling of vmstate and continuation jump instructions, which allow for continuous dynamic tail calls. An attacker can exploit this by crafting a smart contract with deeply nested…
AplazadaAlta (7.5)0.58%—TON BlockchainAITON Virtual MachineAI13/2/202617/6/2026
A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.06. The issue is located in the execution logic of the INMSGPARAM instruction, where the program fails to validate if a specific pointer is null before accessing it. By sending a malicious…
AnalizadaMedia (4.5)0.25%—Oracle Java Virtual Machine20/1/202617/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 and 21.3-21.20. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise Java VM. Successful attacks require…
AnalizadaMedia (5.9)0.23%—Oracle Java Virtual Machine21/10/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can…
AnalizadaAlta (7.7)0.32%—Oracle Java Virtual Machine15/7/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. While the…
AnalizadaAlta (7.4)0.37%—Oracle Java Virtual Machine15/4/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability…
AnalizadaAlta (7.8)0.88%—Microsoft System Center Data Protection ManagerMicrosoft System Center Operations ManagerMicrosoft System Center OrchestratorMicrosoft System Center Service Manager+18/4/202517/6/2026
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.14%—Dell Recoverpoint FOR Virtual Machines20/2/202517/6/2026
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the system.
AnalizadaAlta (7.8)0.16%—Dell Recoverpoint FOR Virtual Machines20/2/202517/6/2026
Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running the specific binary and perform any administrative action permitted by it resulting in shutting down the server, modifying…
AnalizadaMedia (4.2)0.25%—Oracle Java Virtual Machine21/1/202517/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.…
AnalizadaMedia (6.5)0.47%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could potentially exploit this vulnerability, leading to the disruption of most functionalities of the RPA persistent after reboot, resulting in need of technical support intervention in getting system back…
AnalizadaCrítica (9.8)0.55%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaMedia (5.5)0.19%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.
AnalizadaMedia (6.5)0.56%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information
ModificadaCrítica (9.8)0.41%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to…
AnalizadaCrítica (9.8)0.32%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete…
AnalizadaAlta (8.8)0.78%—Dell Recoverpoint FOR Virtual Machines13/12/202417/6/2026
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system.
ModificadaAlta (8.1)1.1%—Microsoft Azure Data Science Virtual Machine11/6/202420/7/2026
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
AnalizadaMedia (5.3)0.43%—Oracle Java Virtual Machine16/4/202417/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful…
AnalizadaCrítica (9.8)1.4%—Dell Recoverpoint FOR Virtual Machines16/2/202417/6/2026
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete…