Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 1.2% | — | Asus Asmb9-ikvm FirmwareAsus Rs720a-e9-rs24-e FirmwareAsus Rs700a-e9-rs4 FirmwareAsus Rs700-e9-rs4 Firmware+40 | 6/4/2021 | 17/6/2026 | The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. | |
| Modificada | Alta (7.8) | 0.25% | — | Tibco Enterprise Message Service | 23/3/2021 | 17/6/2026 | The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration (tibemsca), Enterprise Message Service JSON configuration generator (tibemsconf2json), and Enterprise Message Service C API components of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message… | |
| Modificada | Alta (7.8) | 0.22% | — | Tibco Enterprise Message Service | 23/3/2021 | 17/6/2026 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of… | |
| Modificada | Media (5.5) | 0.55% | — | Pybitmessage | 8/2/2021 | 17/6/2026 | PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted apinotifypath value. NOTE: the discoverer states "security mitigation may not be necessary as there is no evidence yet that these screen intercepts are actually transported away from the local… | |
| Modificada | Crítica (9.8) | 1.6% | — | Sagemcom F@st 3686 Firmware | 26/1/2021 | 17/6/2026 | Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI. | |
| Modificada | Media (5.3) | 3.6% | — | Avanquest Expert PDF UltimateAvanquest PDF Experte UltimateFoxitsoftware Foxit ReaderGonitro Nitro PRO+13 | 7/1/2021 | 17/6/2026 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the… | |
| Modificada | Media (5.3) | 1.1% | — | Sagemcom F@st 3486 Router Firmware | 27/11/2020 | 17/6/2026 | Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via the /backupsettings.conf URI, when any valid session is running. | |
| Modificada | Media (5.4) | 0.53% | — | Sage Easypay | 18/10/2020 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web script or HTML via multiple parameters through Unicode Transformations (Best-fit Mapping), as demonstrated by the full-width variants of the less-than sign (%EF%BC%9C) and… | |
| Modificada | Media (6.1) | 0.92% | — | Sagedpw Sage DPW | 16/10/2020 | 17/6/2026 | An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog is vulnerable to Reflected XSS. If the attacker can lure a user into clicking a crafted link, he can execute arbitrary JavaScript code in the user's browser. The vulnerability can be used to change… | |
| Modificada | Media (6.1) | 1.0% | — | Sagedpw Sage DPW | 16/10/2020 | 17/6/2026 | An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses claiming functionality. However, to view the file, authentication is required. By exploiting this vulnerability, an attacker can persistently include arbitrary HTML or… | |
| Modificada | Media (6.1) | 0.73% | — | Sagemcom F@st 3686 Firmware | 14/9/2020 | 9/7/2026 | Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp. | |
| Modificada | Alta (8.8) | 3.7% | — | Sagemcom F@st 5280 Router Firmware | 1/9/2020 | 17/6/2026 | Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request with valid sess_id, nonce, and ha1 values inside of the serialized session cookie, an attacker may alter the user value… | |
| Modificada | Crítica (9.8) | 3.9% | — | Diskusage-ng Project Diskusage-ng | 6/4/2020 | 17/6/2026 | diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument. | |
| Modificada | Alta (8.1) | 2.1% | — | Gurux Device Language Message Specification Director | 25/2/2020 | 17/6/2026 | An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable files and place them in an autorun… | |
| Modificada | Alta (8.1) | 1.0% | 💥 PoC | Gurux Device Language Message Specification Director | 25/2/2020 | 17/6/2026 | Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and gurux.fi/updates/updates.xml. Then, the attacker can modify the… | |
| Modificada | Media (6.5) | 1.6% | — | Messagepack | 31/1/2020 | 17/6/2026 | MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions and stack overflow. Review the linked GitHub Security Advisory for more information and remediation steps. | |
| Modificada | Crítica (9.8) | 4.5% | — | IBM IOT MessagesightIBM Watson IOT Platform - Message Gateway | 28/1/2020 | 17/6/2026 | IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker could overflow a buffer and execute… | |
| Modificada | Media (6.1) | 1.0% | — | HP Enhanced Internet Usage Manager | 16/1/2020 | 17/6/2026 | A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0. The vulnerability could be used for unauthorized access to information via cross site scripting. HPE has made the following software updates to resolve the vulnerability in eIUM. The eIUM 8.3 FP01… | |
| Modificada | Alta (8.8) | 23% | — | Sagemcom F@st 3890 FirmwareSagemcom F@st 3686 FirmwareNetgear Cg3700emr FirmwareNetgear C6250emr Firmware+3 | 9/1/2020 | 17/6/2026 | Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to… | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to… | |
| Modificada | Media (6.1) | 0.82% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5. | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5. | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to… | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the LDAP cbURL parameter of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions… | |
| Modificada | Media (6.1) | 0.84% | — | Telos Automated Message Handling System | 3/1/2020 | 17/6/2026 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to… |