Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of user-supplied input on… | |
| Modificada | Alta (7.2) | 1.8% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input in the Certificate Signing Request… | |
| Modificada | Alta (7.2) | 3.8% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied input by the affected software.… | |
| Modificada | Alta (7.8) | 0.41% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to obtain root privileges. The vulnerability is due to insufficient validation of user-supplied input… | |
| Modificada | Alta (7.2) | 3.3% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an affected device. The vulnerability is due to improper… | |
| Modificada | Alta (8.8) | 3.6% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of user-supplied… | |
| Modificada | Alta (8.8) | 2.6% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. The vulnerability is due to insufficient validation of command input by… | |
| Modificada | Alta (8.1) | 1.7% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this… | |
| Modificada | Alta (7.2) | 3.5% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. An attacker would need to have valid administrator credentials on the… | |
| Modificada | Alta (7.2) | 2.8% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing… | |
| Modificada | Media (6.7) | 0.61% | — | Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+23 | 13/5/2019 | 17/6/2026 | A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based… | |
| Modificada | Media (5) | 0.83% | — | Omron Cx-supervisor | 12/2/2019 | 17/6/2026 | When CX-Supervisor (Versions 3.42 and prior) processes project files and tampers with the value of an offset, an attacker can force the application to read a value outside of an array. | |
| Modificada | Alta (7.3) | 1.2% | — | Omron Cx-supervisor | 12/2/2019 | 17/6/2026 | An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application. | |
| Modificada | Alta (7.3) | 1.5% | — | Omron Cx-supervisor | 28/1/2019 | 17/6/2026 | An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application. | |
| Modificada | Alta (7.3) | 1.5% | — | Omron Cx-supervisor | 22/1/2019 | 17/6/2026 | A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application. | |
| Modificada | Alta (8.8) | 2.4% | — | Omron Cx-supervisor | 22/1/2019 | 17/6/2026 | Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the… | |
| Modificada | Media (5) | 0.75% | — | Omron Cx-supervisor | 22/1/2019 | 17/6/2026 | An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. | |
| Modificada | Alta (8.8) | 2.4% | — | Omron Cx-supervisor | 22/1/2019 | 17/6/2026 | CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application. | |
| Modificada | Alta (7.8) | 1.6% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application. | |
| Modificada | Alta (7.8) | 1.6% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application. | |
| Modificada | Baja (3.3) | 0.89% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array. | |
| Modificada | Alta (7.8) | 1.1% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object. | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Unified Computing System DirectorCisco Integrated Management Controller Supervisor | 5/10/2018 | 17/6/2026 | A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of… | |
| Modificada | Media (4.4) | 0.34% | — | Avaya Call Management System Supervisor | 24/9/2018 | 17/6/2026 | A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x. |