Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

352 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.2%—Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic15/6/202017/6/2026
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000…
ModificadaCrítica (9.8)12%—Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic15/6/202017/6/2026
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000…
ModificadaAlta (8.1)2.8%—Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic15/6/202017/6/2026
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000…
ModificadaCrítica (9.9)1.7%—Nextcloud Talk8/6/202017/6/2026
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
ModificadaCrítica (9.8)5.5%—Rockwellautomation Factorytalk Services Platform23/3/202017/6/2026
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.
ModificadaBaja (2.7)0.77%—Nextcloud Talk4/2/202017/6/2026
Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.
ModificadaMedia (4.8)0.84%—Nextcloud DeckNextcloud ServerNextcloud Talk4/2/202017/6/2026
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
ModificadaAlta (7.5)1.0%—Jetbrains Idetalk15/1/202017/6/2026
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
ModificadaCrítica (9.8)3.6%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
ModificadaCrítica (9.8)3.6%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
ModificadaCrítica (9.8)3.4%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arbitrary code as the root user.
ModificadaCrítica (9.8)3.4%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
A stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to cause denial of service or run arbitrary code as the root user.
ModificadaCrítica (9.8)3.3%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
ModificadaCrítica (9.8)3.6%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
ModificadaAlta (8.1)0.95%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user.
ModificadaAlta (7.5)1.1%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades and alter device settings.
ModificadaCrítica (9.8)3.7%—Skymee Petalk AI FirmwarePetwant Pf-103 Firmware13/12/201917/6/2026
processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
ModificadaMedia (6.1)1.3%—Cleantalk Spam Protection, Antispam, Firewall13/11/201917/6/2026
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack…
ModificadaCrítica (9.8)1.8%—Techytalk Quick Chat18/7/201917/6/2026
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.
ModificadaMedia (6.1)0.85%—Esotalk29/4/201917/6/2026
esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.
ModificadaAlta (7.8)1.3%—Hmtalk Daviewindy25/4/201917/6/2026
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed Image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
ModificadaAlta (8.8)1.3%—Jenkins AWS Elastic Beanstalk Publisher4/4/201917/6/2026
Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaAlta (8.8)2.3%—Kakaocorp Kakaotalk1/4/201917/6/2026
Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the message window. This affects KaKaoTalk windows version 2.7.5.2024 or lower.
ModificadaAlta (7.5)3.9%—Rockwellautomation Factorytalk Services Platform24/1/201917/6/2026
In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial or complete denial-of-service condition to the affected services.
ModificadaCrítica (9.8)87%💥 ExploitNetatalkSynology Router ManagerSynology SkynasSynology Diskstation Manager+220/12/201817/6/2026
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
Orbitaley — Vulnerabilidades