Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.17% | — | Samsung Factorycamerafb | 7/10/2022 | 17/6/2026 | Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege. | |
| Modificada | Media (6.3) | 0.21% | — | Opensuse Factory | 7/9/2022 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3. | |
| Modificada | Media (4.9) | 0.84% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x. | |
| Modificada | Media (6.1) | 0.57% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before… | |
| Modificada | Alta (8.8) | 0.36% | — | Jfrog Artifactory | 6/7/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x. | |
| Modificada | Media (6.5) | 1.3% | — | Webfactoryltd External Links IN NEW Window / NEW TAB | 30/5/2022 | 17/6/2026 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur. | |
| Modificada | Media (6.1) | 0.79% | — | Webfactoryltd External Links IN NEW Window / NEW TAB | 30/5/2022 | 17/6/2026 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible. | |
| Modificada | Media (6.5) | 0.57% | — | Jfrog Artifactory | 23/5/2022 | 17/6/2026 | JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation. | |
| Modificada | Media (4.9) | 0.54% | — | Jfrog Artifactory | 19/5/2022 | 17/6/2026 | JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators. | |
| Modificada | Alta (8.8) | 2.1% | — | Jfrog Artifactory | 16/5/2022 | 17/6/2026 | JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized… | |
| Modificada | Alta (7.8) | 0.24% | — | Samsung Factorycamera | 11/4/2022 | 17/6/2026 | Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege. | |
| Modificada | Alta (8.8) | 2.4% | — | Rockwellautomation Factorytalk Services Platform | 1/4/2022 | 17/6/2026 | Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have… | |
| Modificada | Crítica (9.8) | 4.1% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier. | |
| Modificada | Alta (7.5) | 1.6% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 5.7% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.8% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.5% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.9% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.5% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.8% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.2% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk… | |
| Modificada | Baja (2.7) | 0.65% | — | Jfrog Artifactory | 2/3/2022 | 17/6/2026 | JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation. | |
| Modificada | Media (5.4) | 0.63% | — | Jfrog Artifactory | 2/3/2022 | 17/6/2026 | JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session. | |
| Modificada | Alta (7.8) | 0.16% | — | Rockwellautomation Factorytalk View | 24/2/2022 | 17/6/2026 | The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the… | |
| Modificada | Media (5.5) | 0.27% | — | Rockwellautomation Factorytalk View | 24/2/2022 | 17/6/2026 | Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials. |