Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 17% | 💥 Exploit | Aveva Indusoft WEB StudioAveva Intouch Machine Edition 2014 | 13/2/2019 | 17/6/2026 | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine. | |
| Analizada | Media (5.5) | 0.34% | — | Dokan-dev DokanyNomachine | 10/12/2018 | 17/6/2026 | The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read. | |
| Modificada | Alta (7.1) | 0.41% | — | Dell EMC RecoverpointDell EMC Recoverpoint FOR Virtual Machines | 13/11/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulnerability. A malicious boxmgmt user may potentially be able to consume large amount of CPU bandwidth to make the system slow or to determine the existence of any system… | |
| Modificada | Media (5.5) | 0.42% | — | EMC RecoverpointEMC Recoverpoint FOR Virtual Machines | 13/11/2018 | 17/6/2026 | Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A malicious boxmgmt user may potentially be able to determine the existence of any system file via Boxmgmt CLI. | |
| Modificada | Alta (8.2) | 0.66% | — | Schneider-electric Somachine Basic | 2/11/2018 | 17/6/2026 | A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device. | |
| Modificada | Crítica (9.8) | 3.7% | — | Aveva Indusoft WEB StudioAveva EdgeAveva Intouch Machine Edition 2014 | 2/11/2018 | 17/6/2026 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with… | |
| Modificada | Crítica (9.8) | 4.6% | — | Aveva Indusoft WEB StudioAveva EdgeAveva Intouch Machine Edition 2014 | 2/11/2018 | 17/6/2026 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine… | |
| Modificada | Media (6.5) | 1.1% | — | Rainmachine WEB Application | 1/11/2018 | 17/6/2026 | A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request. | |
| Modificada | Crítica (9.8) | 1.6% | — | Rainmachine Mini-8 FirmwareRainmachine Touch HD 12 Firmware | 1/11/2018 | 17/6/2026 | An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in the HTTP 'Host' header, as demonstrated by retrieving credentials. | |
| Modificada | Alta (8.8) | 0.49% | — | Rainmachine WEB Application | 1/11/2018 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to control the RainMachine device via the REST API. | |
| Modificada | Media (6.1) | 0.68% | — | Rainmachine WEB Application | 1/11/2018 | 17/6/2026 | A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to inject arbitrary JavaScript via the REST API. | |
| Modificada | Crítica (9.8) | 1.3% | — | Rainmachine Mini-8 Firmware | 1/11/2018 | 17/6/2026 | The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function. | |
| Modificada | Alta (8.1) | 1.1% | — | Rainmachine Mini-8 Firmware | 1/11/2018 | 17/6/2026 | The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2nd generation) uses the administrator's password hash to generate a 6-digit temporary passcode that can be used for remote and local access, aka a "Use of Password Hash Instead of Password for… | |
| Modificada | Alta (7.8) | 4.6% | 💥 Exploit | Nomachine | 15/10/2018 | 17/6/2026 | NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as a .nxs file, as demonstrated by a scenario where the .nxs file and the DLL are in the current working directory, and the Trojan horse code is executed. (The directory… | |
| Modificada | Alta (8.8) | 1.6% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 21/9/2018 | 17/6/2026 | An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input WebAssembly file's main function, which allows attackers to cause a denial of service (application crash by NULL… | |
| Modificada | Media (6.5) | 1.2% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 21/9/2018 | 17/6/2026 | An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file magic comparison, allowing attackers to cause a Denial of Service (application crash caused by out-of-bounds read) by crafting a file that has fewer than 4 bytes. | |
| Modificada | Alta (8.8) | 1.3% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 10/9/2018 | 17/6/2026 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because a certain new_allocator allocate call fails. | |
| Modificada | Alta (8.8) | 1.3% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 10/9/2018 | 17/6/2026 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because libRuntime.so!llvm::InstructionCombiningPass::runOnFunction is mishandled. | |
| Modificada | Alta (8.8) | 1.3% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 10/9/2018 | 17/6/2026 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in IR::FunctionValidationContext::end. | |
| Modificada | Alta (8.8) | 1.3% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 10/9/2018 | 17/6/2026 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::popAndValidateOperand. | |
| Modificada | Alta (8.8) | 1.3% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 10/9/2018 | 17/6/2026 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because Errors::unreachable() is reached. | |
| Modificada | Alta (8.8) | 1.3% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 10/9/2018 | 17/6/2026 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::else_. | |
| Modificada | Alta (8.8) | 1.3% | — | Webassembly Virtual Machine Project Webassembly Virtual Machine | 10/9/2018 | 17/6/2026 | In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an IR::FunctionValidationContext::catch_all heap-based buffer over-read. | |
| Modificada | Crítica (9.8) | 1.7% | — | Nomachine | 4/9/2018 | 17/6/2026 | A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.2% | — | Aveva Indusoft WEB StudioAveva Intouch Machine 2017 | 19/7/2018 | 17/6/2026 | AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. |