Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 1.0% | — | Microsoft Entra Provisioning Service | 7/8/2026 | 7/8/2026 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Entra Provisioning Service | 2/7/2026 | 8/7/2026 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Media (6.6) | 0.35% | — | SAP Operational Data Provisioning Data Replication APIAI | 9/6/2026 | 23/7/2026 | The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permitted SAP-internal applications and are being used by customer or third-party applications in ways that are not aligned with its intended usage. Which could lead to… | |
| Analizada | Alta (8.7) | 0.39% | — | Suse Local Path Provisioner | 28/5/2026 | 17/6/2026 | Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-path-provisioner. The… | |
| Analizada | Baja (2.7) | 0.31% | — | Canonical Ubuntu Desktop Provision | 9/4/2026 | 30/9/2026 | In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs. | |
| Aplazada | Media (4.8) | 0.22% | — | Stvs ProvisionAI | 31/12/2025 | 17/6/2026 | STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authenticated attackers to inject arbitrary HTML code. Attackers can exploit the unvalidated input to execute malicious scripts within a user's browser session in the context of the affected site. | |
| Analizada | Alta (7.1) | 0.77% | — | Stvs Provision | 9/12/2025 | 17/6/2026 | STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files… | |
| Analizada | Media (6.9) | 0.20% | — | Stvs Provision | 9/12/2025 | 17/6/2026 | STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users. | |
| Aplazada | Alta (8.6) | 1.8% | — | Lantronix Provisioning ManagerAI | 22/7/2025 | 17/6/2026 | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed. | |
| Aplazada | Media (6.8) | 0.28% | — | Okta On-premises ProvisioningAI | 22/7/2025 | 17/6/2026 | Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by… | |
| Analizada | Media (5.3) | 0.55% | — | Oracle Fleet Patching AND Provisioning | 15/4/2025 | 17/6/2026 | Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.3-19.26. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and amp; Provisioning. Successful attacks of… | |
| Aplazada | Alta (7.6) | 0.29% | — | Kanidm Kanidim-provisionAI | 24/3/2025 | 17/6/2026 | kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (optional) kanidm patches provided by kandim-provision will cause the provisioned admin credentials to be leaked to the system log. This only… | |
| Aplazada | Baja (3.5) | 0.60% | — | Mavenir SCE Application Provisioning PortalAI | 12/2/2025 | 17/6/2026 | A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an administrative user to access system files with the file permissions of the privileged system user running the application. | |
| Aplazada | Alta (8.8) | 0.39% | — | Mavenir SCE Application Provisioning PortalAI | 12/2/2025 | 17/6/2026 | An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls. | |
| Aplazada | Alta (7.1) | 0.32% | — | Realtyna ProvisioningAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna Provisioning realtyna-provisioning allows Reflected XSS.This issue affects Realtyna Provisioning: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.9) | 0.43% | — | Provision ISR Sh-4050a-2AIProvision ISR Sh-4100a-2lAIProvision ISR Sh-8100a-2lAIProvision ISR Sh-16200a-2AI+2 | 5/1/2025 | 17/6/2026 | A vulnerability was found in Provision-ISR SH-4050A-2, SH-4100A-2L(MM), SH-8100A-2L(MM), SH-16200A-2(1U), SH-16200A-5(1U) and NVR5-8200PX up to 20241220. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /server.js. The manipulation leads to information… | |
| Aplazada | Media (5.3) | 0.37% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows… | |
| Aplazada | Alta (7.5) | 0.64% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet allows remote attackers to retrieve any file from the Kurmi web application installation folder, e.g., files such as the obfuscated… | |
| Aplazada | Media (4.9) | 0.84% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal and Local File Inclusion vulnerability in the logsSys.do page allows remote attackers (authenticated as administrators) to trigger the display of unintended files. Any file accessible to the Kurmi… | |
| Aplazada | Media (4.8) | 0.27% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15 allows remote attackers (authenticated as system administrators) to inject arbitrary web script or HTML via the COMPONENT_fields(htmlTitle)… | |
| Aplazada | Crítica (9.4) | 0.53% | — | Kurmi Provisioning SuiteAI | 27/12/2024 | 17/6/2026 | An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be… | |
| Analizada | Media (5.4) | 0.16% | — | Intel Server Debug AND Provisioning Tool | 13/11/2024 | 17/6/2026 | Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.15% | — | Intel Server Debug AND Provisioning Tool | 13/11/2024 | 17/6/2026 | Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access. | |
| Analizada | Alta (7.3) | 0.27% | — | AMD Provisioning Console | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Analizada | Media (5.5) | 0.14% | — | Lenovo Dolby Vision Provisioning | 11/10/2024 | 17/6/2026 | A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning software prior to version 2.0.0.2 that could allow a local attacker to read files on the system with elevated privileges during installation of the package. Previously installed versions are not affected by… |