Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.77% | — | IBM Data Virtualization Manager FOR Z/os | 26/11/2024 | 17/6/2026 | IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server. | |
| Modificada | Media (5.5) | 0.39% | — | Redhat Ansible Automation Platform Early AccessRedhat Ansible EngineRedhat OpenstackRedhat Virtualization+5 | 3/3/2022 | 17/6/2026 | A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Media (6.5) | 3.1% | — | Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+156 | 14/11/2019 | 17/6/2026 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | |
| Modificada | Baja (3.1) | 0.35% | — | Redhat Enterprise Virtualization Manager | 9/11/2019 | 16/6/2026 | In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network… | |
| Modificada | Media (6.1) | 0.91% | — | Redhat CloudformsRedhat Manageiq Enterprise Virtualization Manager | 1/11/2019 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.1) | 5.0% | — | LodashNetapp Active IQ Unified ManagerNetapp Service Level ManagerRedhat Virtualization Manager+17 | 26/7/2019 | 17/6/2026 | Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. | |
| Modificada | Media (5.5) | 0.34% | — | OvirtRedhat Virtualization Manager | 11/7/2019 | 17/6/2026 | Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts. | |
| Modificada | Media (6.1) | 87% | — | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Media (6.1) | 16% | — | Getbootstrap BootstrapF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+12 | 20/2/2019 | 17/6/2026 | In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. | |
| Modificada | Alta (7.5) | 2.2% | — | RsyslogRedhat Virtualization ManagerRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+8 | 25/1/2019 | 17/6/2026 | A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable. | |
| Modificada | Crítica (9.8) | 4.7% | — | QemuDebian LinuxCanonical Ubuntu LinuxRedhat Openstack+2 | 9/10/2018 | 17/6/2026 | qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact. | |
| Modificada | Alta (7.5) | 6.3% | — | QemuCanonical Ubuntu LinuxDebian LinuxRedhat Virtualization+1 | 9/10/2018 | 17/6/2026 | Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used. | |
| Modificada | Crítica (9.8) | 4.8% | — | Redhat Openshift Container PlatformRedhat OpenstackRedhat Storage ConsoleRedhat Virtualization+5 | 19/7/2018 | 17/6/2026 | Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in code execution. By default, the jinja2 templating language is now… | |
| Modificada | Crítica (9.8) | 0.99% | — | OvirtRedhat Enterprise Virtualization Manager | 26/6/2018 | 17/6/2026 | ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords. | |
| Modificada | Media (5.5) | 61% | — | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Alta (7.8) | 18% | — | Debian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+7 | 8/5/2018 | 17/6/2026 | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example)… | |
| Modificada | Alta (8.8) | 0.75% | — | Redhat Manageiq Enterprise Virtualization Manager | 1/5/2018 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. | |
| Modificada | Media (6.1) | 0.86% | — | Canonical Ubuntu LinuxRedhat Ceph StorageRedhat Enterprise Linux Fast DatapathRedhat Openshift+5 | 24/4/2018 | 17/6/2026 | The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are… | |
| Modificada | Crítica (9.1) | 3.4% | — | Redhat Enterprise Virtualization Manager | 25/9/2017 | 17/6/2026 | redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment. | |
| Modificada | Media (5.9) | 1.9% | — | Redhat Enterprise Virtualization Manager | 24/8/2017 | 17/6/2026 | Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable. | |
| Modificada | Crítica (9.8) | 2.9% | — | OpenvswitchDebian LinuxRedhat OpenstackRedhat Virtualization+1 | 23/5/2017 | 17/6/2026 | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`. | |
| Modificada | Media (4.7) | 1.4% | — | Solarwinds Virtualization Manager | 24/6/2016 | 17/6/2026 | SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack. | |
| Analizada | Alta (7.8) | 3.7% | ⚠ Explotación activa | Solarwinds Virtualization Manager | 17/6/2016 | 17/6/2026 | SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd." | |
| Modificada | Crítica (9.8) | 13% | — | Solarwinds Virtualization Manager | 17/6/2016 | 17/6/2026 | The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. | |
| Modificada | Baja (2.1) | 0.38% | — | Redhat Enterprise Virtualization Manager | 1/5/2015 | 17/6/2026 | Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory. |