Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.22% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge. | |
| Analizada | Media (5.4) | 0.24% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | InfoScale VIOM 9.1.3 allows XSS. | |
| Analizada | Media (6.5) | 0.35% | — | Veritas Infoscale Operations Manager | 20/5/2026 | 23/7/2026 | SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. | |
| Analizada | Alta (8.8) | 1.1% | — | Microsoft System Center Operations Manager | 10/3/2026 | 17/6/2026 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.88% | — | Microsoft System Center Data Protection ManagerMicrosoft System Center Operations ManagerMicrosoft System Center OrchestratorMicrosoft System Center Service Manager+1 | 8/4/2025 | 17/6/2026 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.8) | 20% | — | Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 0.99% | — | Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+4 | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Media (6.5) | 1.4% | — | Microsoft System Center Operations Manager | 14/11/2023 | 17/6/2026 | Open Management Infrastructure Information Disclosure Vulnerability | |
| Modificada | Alta (8.8) | 0.90% | — | Veritas Infoscale Operations Manager | 17/7/2023 | 17/6/2026 | The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server. | |
| Modificada | Crítica (9.8) | 0.58% | — | Veritas Infoscale Operations Manager | 10/5/2023 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to submit arbitrary SQL commands on the… | |
| Modificada | Alta (7.2) | 0.70% | — | Veritas Infoscale Operations Manager | 10/5/2023 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application does not validate user-supplied data and appends it to OS commands and internal binaries used by the application. An attacker with root/administrator level privileges can leverage… | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager | 9/8/2022 | 17/6/2026 | System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.92% | — | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+6 | 15/6/2022 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Media (4.9) | 2.7% | — | Veritas Infoscale Operations Manager | 4/3/2022 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By… | |
| Modificada | Media (4.8) | 0.45% | — | Veritas Infoscale Operations Manager | 4/3/2022 | 17/6/2026 | An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.5) | 2.9% | — | Microsoft System Center Operations Manager | 13/10/2021 | 17/6/2026 | SCOM Information Disclosure Vulnerability | |
| Analizada | Alta (7.8) | 2.9% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 11% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 1.2% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure. | |
| Modificada | Alta (7.5) | 1.1% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure. | |
| Modificada | Alta (7.5) | 0.81% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster. | |
| Modificada | Alta (7.5) | 1.0% | — | Vmware Cloud FoundationVmware Vrealize Operations ManagerVmware Vrealize Suite Lifecycle Manager | 30/8/2021 | 17/6/2026 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure. |