Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

413 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.17%—Samsung Factorycamerafb7/10/202217/6/2026
Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege.
ModificadaMedia (6.3)0.21%—Opensuse Factory7/9/202217/6/2026
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.
ModificadaMedia (4.9)0.84%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
ModificadaMedia (6.1)0.57%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one of the XHR parameters in Users REST API endpoint. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.36.1 versions prior to 7.29.8; JFrog Artifactory versions before…
ModificadaAlta (8.8)0.36%—Jfrog Artifactory6/7/202217/6/2026
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
ModificadaMedia (6.5)1.3%—Webfactoryltd External Links IN NEW Window / NEW TAB30/5/202217/6/2026
The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.
ModificadaMedia (6.1)0.79%—Webfactoryltd External Links IN NEW Window / NEW TAB30/5/202217/6/2026
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.
ModificadaMedia (6.5)0.57%—Jfrog Artifactory23/5/202217/6/2026
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to improper permissions validation.
ModificadaMedia (4.9)0.54%—Jfrog Artifactory19/5/202217/6/2026
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.
ModificadaAlta (8.8)2.1%—Jfrog Artifactory16/5/202217/6/2026
JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized…
ModificadaAlta (7.8)0.24%—Samsung Factorycamera11/4/202217/6/2026
Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.
ModificadaAlta (8.8)2.4%—Rockwellautomation Factorytalk Services Platform1/4/202217/6/2026
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have…
ModificadaCrítica (9.8)4.1%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
ModificadaAlta (7.5)1.6%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)5.7%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
ModificadaCrítica (9.8)3.8%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.5%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
ModificadaCrítica (9.8)3.9%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.5%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
ModificadaCrítica (9.8)3.8%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.2%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk…
ModificadaBaja (2.7)0.65%—Jfrog Artifactory2/3/202217/6/2026
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
ModificadaMedia (5.4)0.63%—Jfrog Artifactory2/3/202217/6/2026
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
ModificadaAlta (7.8)0.16%—Rockwellautomation Factorytalk View24/2/202217/6/2026
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the…
ModificadaMedia (5.5)0.27%—Rockwellautomation Factorytalk View24/2/202217/6/2026
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
Orbitaley — Vulnerabilidades