Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.31%—Devolutions Remote Desktop Manager6/12/202317/6/2026
Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaCrítica (9.8)0.74%—Remoteclinic Remote Clinic7/11/202317/6/2026
RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.
ModificadaAlta (8.8)1.9%—Remoteclinic Remote Clinic7/11/202317/6/2026
RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by a lack of input validation and access…
ModificadaCrítica (9.8)0.74%—Remoteclinic Remote Clinic7/11/202317/6/2026
RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
ModificadaCrítica (9.8)0.74%—Remoteclinic Remote Clinic7/11/202317/6/2026
RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
ModificadaCrítica (9.8)0.58%—Devolutions Remote Desktop Manager1/11/202317/6/2026
A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.
ModificadaCrítica (9.8)0.61%—Devolutions Remote Desktop Manager1/11/202317/6/2026
Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.
ModificadaMedia (6.5)0.62%—Cybozu Remote Service1/11/202317/6/2026
Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated attacker to consume huge storage space or cause significantly delayed communication.
ModificadaCrítica (9.8)0.80%—Tsplus Remote Work17/10/202317/6/2026
TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. This may enable privilege escalation if a different local user modifies a file. NOTE: CVE-2023-31067 and CVE-2023-31068 are only about the TSplus Remote Access product,…
ModificadaCrítica (9.8)0.91%—Tsplus Remote Work17/10/202317/6/2026
TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about the TSplus Remote Access product, not the TSplus Remote Work product.
ModificadaAlta (7.8)0.19%—Beyondtrust Privileged Remote Access12/10/202317/6/2026
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.
ModificadaAlta (8.8)0.26%—Buildfail Localize Remote Images3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Buildfail Localize Remote Images plugin <= 1.0.9 versions.
ModificadaAlta (8.8)1.2%—Deyue Remote Vehicle Management System Project Deyue Remote Vehicle Management System2/10/202317/6/2026
Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.
ModificadaCrítica (9.8)1.3%—Eclipse Remote Application Platform21/9/202317/6/2026
In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. The reason for this is a not completely secure extraction of the file name in the FileUploadProcessor.stripFileName(String name) method. As soon as this finds a / in the…
AnalizadaCrítica (9.8)3.7%💥 ExploitTsplus Remote Work11/9/202317/6/2026
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.
AnalizadaCrítica (9.8)5.4%💥 ExploitTsplus Remote Work11/9/202317/6/2026
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.
ModificadaCrítica (9.8)5.5%💥 ExploitTsplus Remote Access11/9/202317/6/2026
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.
ModificadaCrítica (9.8)1.8%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support5/9/202317/6/2026
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating…
ModificadaAlta (8.1)0.34%—Etictelecom Remote Access Server Firmware23/8/202317/6/2026
ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default. This could allow an attacker with adjacent network access to alter the configuration of the device or cause a denial-of-service condition.
ModificadaMedia (6.5)0.54%—Devolutions Remote Desktop Manager21/8/202317/6/2026
Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write…
ModificadaCrítica (9.8)0.72%—Devolutions Remote Desktop Manager21/8/202317/6/2026
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.
ModificadaMedia (4.3)0.74%—Froger WP Remote Users Sync16/8/202317/6/2026
The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to…
ModificadaMedia (5.4)0.73%—Froger WP Remote Users Sync16/8/202317/6/2026
The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from…
ModificadaCrítica (9.8)0.63%—Farmakom Remote Administration Console8/8/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02.
Orbitaley — Vulnerabilidades