Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.48% | — | LokkaAIMicrosoft 365AIMicrosoft GraphAIMicrosoft Azure Resource ManagerAI | 15/9/2026 | 30/9/2026 | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can… | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Resource Manager | 22/5/2026 | 23/7/2026 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure LocalMicrosoft Azure Resource Manager | 18/5/2026 | 17/6/2026 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | |
| Modificada | Alta (8.8) | 0.68% | — | Microsoft Azure Resource Manager | 23/1/2026 | 30/7/2026 | Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.40% | — | Dell Storage Monitoring AND ReportingDell Storage Resource Manager | 12/4/2024 | 17/6/2026 | Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session. | |
| Modificada | Crítica (9.8) | 3.2% | — | Dell Storage Monitoring AND ReportingDell Storage Resource Manager | 12/4/2021 | 17/6/2026 | Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to arbitrary privileged code execution on the vulnerable application. The severity is Critical as this may… | |
| Modificada | Crítica (9.8) | 6.7% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Crítica (9.8) | 4.2% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Crítica (9.8) | 4.2% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Alta (7.5) | 3.3% | — | Yokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry ClassYokogawa Centum VP FirmwareYokogawa Centum VP Entry Class+5 | 9/1/2019 | 17/6/2026 | Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 -… | |
| Modificada | Alta (7) | 1.2% | — | Polycom Realpresence Resource Manager | 19/9/2017 | 17/6/2026 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts, related to a sudo misconfiguration. | |
| Modificada | Media (6.5) | 4.9% | — | Polycom Realpresence Resource Manager | 19/9/2017 | 17/6/2026 | Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. (dot dot) in the Modifier parameter to PlcmRmWeb/FileDownload; or remote authenticated administrators to upload arbitrary files via the (2)… | |
| Modificada | Crítica (9.8) | 6.9% | — | Polycom Realpresence Resource Manager | 19/9/2017 | 17/6/2026 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests. | |
| Modificada | Media (6.5) | 5.2% | — | Polycom Realpresence Resource Manager | 19/9/2017 | 17/6/2026 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager. | |
| Modificada | Alta (7.8) | 1.7% | — | Polycom Realpresence Resource Manager | 19/9/2017 | 17/6/2026 | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords. | |
| Modificada | Media (6.5) | 0.59% | — | Cisco Videoscape Session Resource Manager | 28/7/2016 | 17/6/2026 | Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813. | |
| Modificada | Alta (7.8) | 1.4% | — | Cisco Videoscape Policy Resource Manager | 21/7/2015 | 17/6/2026 | Cisco Videoscape Policy Resource Manager (PRM) 3.5.4 allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCuu35104 and CSCuu35128. | |
| Modificada | Media (6.8) | 2.8% | — | Adaptivecomputing Torque Resource Manager | 30/10/2014 | 17/6/2026 | The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted session id, which allows remote authenticated users to kill arbitrary processes via a crafted… | |
| Modificada | Alta (10) | 17% | — | Adaptivecomputing Torque Resource Manager | 16/5/2014 | 17/6/2026 | Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.5.13 allows remote attackers to execute arbitrary code via a large count value. | |
| Modificada | Alta (10) | 3.3% | — | Adaptivecomputing Torque Resource Manager | 20/11/2013 | 16/6/2026 | The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the email (-M switch) to qsub. | |
| Modificada | Alta (9) | 2.9% | — | Adaptivecomputing Torque Resource Manager | 11/10/2013 | 16/6/2026 | pbs_mom in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x, 4.x, and earlier does not properly restrict access by unprivileged ports, which allows remote authenticated users to execute arbitrary jobs by submitting a command. | |
| Modificada | Media (4.9) | 0.95% | — | Cluster Resources Torque Resource ManagerClusterresources Torque Resource Manager | 13/1/2012 | 16/6/2026 | Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.9% | — | Clusterresources Torque Resource Manager | 15/8/2011 | 16/6/2026 | Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program. | |
| Modificada | Alta (8.5) | 2.5% | — | Clusterresources Torque Resource Manager | 24/6/2011 | 16/6/2026 | Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.x before 2.4.14, 2.5.x before 2.5.6, and 3.x before 3.0.2 allow (1) remote authenticated users to gain privileges via a long Job_Name field in a qsub command to the server, and might allow (2) local users to… | |
| Modificada | Alta (7.2) | 0.34% | — | Cluster Resources Torque Resource Manager | 3/11/2006 | 16/6/2026 | resmom/start_exec.c in pbs_mom in TORQUE Resource Manager 2.0.0p8 and earlier allows local users to create arbitrary files via a symlink attack on (1) a job output file in /usr/spool/PBS/spool and possibly (2) a job file in /usr/spool/PBS/mom_priv/jobs. |