Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.48%—LokkaAIMicrosoft 365AIMicrosoft GraphAIMicrosoft Azure Resource ManagerAI15/9/202630/9/2026
Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can…
AnalizadaCrítica (9.8)0.90%—Microsoft Azure Resource Manager22/5/202623/7/2026
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure LocalMicrosoft Azure Resource Manager18/5/202617/6/2026
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
ModificadaAlta (8.8)0.68%—Microsoft Azure Resource Manager23/1/202630/7/2026
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)0.40%—Dell Storage Monitoring AND ReportingDell Storage Resource Manager12/4/202417/6/2026
Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session.
ModificadaCrítica (9.8)3.2%—Dell Storage Monitoring AND ReportingDell Storage Resource Manager12/4/202117/6/2026
Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to arbitrary privileged code execution on the vulnerable application. The severity is Critical as this may…
ModificadaCrítica (9.8)6.7%—Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+175/2/202017/6/2026
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and…
ModificadaCrítica (9.8)4.2%—Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+175/2/202017/6/2026
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and…
ModificadaCrítica (9.8)4.2%—Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+175/2/202017/6/2026
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and…
ModificadaAlta (7.5)3.3%—Yokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry ClassYokogawa Centum VP FirmwareYokogawa Centum VP Entry Class+59/1/201917/6/2026
Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 -…
ModificadaAlta (7)1.2%—Polycom Realpresence Resource Manager19/9/201717/6/2026
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts, related to a sudo misconfiguration.
ModificadaMedia (6.5)4.9%—Polycom Realpresence Resource Manager19/9/201717/6/2026
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. (dot dot) in the Modifier parameter to PlcmRmWeb/FileDownload; or remote authenticated administrators to upload arbitrary files via the (2)…
ModificadaCrítica (9.8)6.9%—Polycom Realpresence Resource Manager19/9/201717/6/2026
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.
ModificadaMedia (6.5)5.2%—Polycom Realpresence Resource Manager19/9/201717/6/2026
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager.
ModificadaAlta (7.8)1.7%—Polycom Realpresence Resource Manager19/9/201717/6/2026
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords.
ModificadaMedia (6.5)0.59%—Cisco Videoscape Session Resource Manager28/7/201617/6/2026
Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813.
ModificadaAlta (7.8)1.4%—Cisco Videoscape Policy Resource Manager21/7/201517/6/2026
Cisco Videoscape Policy Resource Manager (PRM) 3.5.4 allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCuu35104 and CSCuu35128.
ModificadaMedia (6.8)2.8%—Adaptivecomputing Torque Resource Manager30/10/201417/6/2026
The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted session id, which allows remote authenticated users to kill arbitrary processes via a crafted…
ModificadaAlta (10)17%—Adaptivecomputing Torque Resource Manager16/5/201417/6/2026
Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.5.13 allows remote attackers to execute arbitrary code via a large count value.
ModificadaAlta (10)3.3%—Adaptivecomputing Torque Resource Manager20/11/201316/6/2026
The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the email (-M switch) to qsub.
ModificadaAlta (9)2.9%—Adaptivecomputing Torque Resource Manager11/10/201316/6/2026
pbs_mom in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x, 4.x, and earlier does not properly restrict access by unprivileged ports, which allows remote authenticated users to execute arbitrary jobs by submitting a command.
ModificadaMedia (4.9)0.95%—Cluster Resources Torque Resource ManagerClusterresources Torque Resource Manager13/1/201216/6/2026
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.
ModificadaAlta (7.5)2.9%—Clusterresources Torque Resource Manager15/8/201116/6/2026
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program.
ModificadaAlta (8.5)2.5%—Clusterresources Torque Resource Manager24/6/201116/6/2026
Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.x before 2.4.14, 2.5.x before 2.5.6, and 3.x before 3.0.2 allow (1) remote authenticated users to gain privileges via a long Job_Name field in a qsub command to the server, and might allow (2) local users to…
ModificadaAlta (7.2)0.34%—Cluster Resources Torque Resource Manager3/11/200616/6/2026
resmom/start_exec.c in pbs_mom in TORQUE Resource Manager 2.0.0p8 and earlier allows local users to create arbitrary files via a symlink attack on (1) a job output file in /usr/spool/PBS/spool and possibly (2) a job file in /usr/spool/PBS/mom_priv/jobs.