Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.23% | — | Opentext Zenworks Service Desk | 18/3/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execute arbitrary JavaScript leading to unauthorized actions on behalf of the user.This issue affects… | |
| Aplazada | Alta (7.4) | 0.23% | — | Opentext Zenworks Configuration ManagementAI | 27/3/2024 | 17/6/2026 | Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue affects ZENworks Configuration Management (ZCM) versions: 2020 update 3, 23.3, and 23.4. | |
| Modificada | Alta (7.2) | 0.87% | — | Microfocus Zenworks | 23/12/2022 | 17/6/2026 | A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in the ZENworks zone but which are outside… | |
| Modificada | Media (6.7) | 0.25% | — | Microfocus Zenworks Configuration ManagementMicrofocus Zenworks Endpoint Security Management | 30/7/2021 | 17/6/2026 | A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges. | |
| Modificada | Alta (7.5) | 1.1% | — | Novell Zenworks Configuration Management | 25/1/2020 | 16/6/2026 | Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information. | |
| Modificada | Media (6.1) | 0.72% | — | Novell Zenworks Configuration Management | 25/1/2020 | 16/6/2026 | Novell ZENworks Configuration Management before 11.2.4 allows XSS. | |
| Modificada | Crítica (9.8) | 24% | — | Novell Zenworks Configuration Management | 9/8/2017 | 17/6/2026 | Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 6.5% | — | Novell Zenworks Configuration Management | 9/8/2017 | 17/6/2026 | com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable. | |
| Modificada | Alta (7.5) | 6.6% | — | Novell Zenworks Configuration Management | 9/8/2017 | 17/6/2026 | Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLogins for the maintenance variable. | |
| Modificada | Media (6.5) | 5.0% | — | Novell Zenworks Configuration Management | 9/8/2017 | 17/6/2026 | The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable. | |
| Modificada | Crítica (9.8) | 7.1% | — | Novell Zenworks Configuration Management | 9/8/2017 | 17/6/2026 | SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.3% | — | Novell Zenworks Configuration Management | 9/8/2017 | 17/6/2026 | Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors. | |
| Modificada | Crítica (9.8) | 8.2% | — | Novell Zenworks Configuration Management | 9/8/2017 | 17/6/2026 | SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.3) | 1.3% | — | Novell Zenworks Configuration Management | 18/2/2016 | 17/6/2026 | The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference. | |
| Modificada | Alta (10) | 74% | — | Novell Zenworks Configuration Management | 7/6/2015 | 17/6/2026 | Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory name in the uid parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST… | |
| Modificada | Alta (10) | 72% | — | Novell Zenworks Configuration Management | 7/6/2015 | 16/6/2026 | Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a zenworks-fileupload request with a crafted directory name in the type parameter, in conjunction with a WAR… | |
| Modificada | Alta (10) | 14% | — | Novell Zenworks Configuration Management | 7/6/2015 | 16/6/2026 | Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a crafted WAR pathname in the filename parameter in conjunction with WAR content in the POST data, a different… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Media (5) | 7.6% | — | Novell Zenworks Configuration Management | 6/3/2014 | 16/6/2026 | Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595. | |
| Modificada | Media (6.8) | 1.2% | — | Novell Zenworks Configuration Management | 2/11/2013 | 17/6/2026 | Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (6.8) | 0.58% | — | Novell Zenworks Configuration Management | 2/11/2013 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (10) | 1.5% | — | Novell Zenworks Configuration Management | 2/11/2013 | 17/6/2026 | Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "Application Exception." | |
| Modificada | Media (4.3) | 0.90% | — | Novell Zenworks Configuration Management | 2/11/2013 | 17/6/2026 | The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors. | |
| Modificada | Media (5) | 5.7% | — | Novell Zenworks Configuration Management | 2/11/2013 | 16/6/2026 | Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to zenworks-unmaninv/. |