Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.6%—Schneider-electric Somachine Basic3/7/201817/6/2026
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml…
ModificadaMedia (6.1)0.71%—Yii2-statemachine13/6/201817/6/2026
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
ModificadaMedia (6.5)2.6%—EMC RecoverpointEMC Recoverpoint FOR Virtual Machines29/5/201817/6/2026
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contains a command injection vulnerability in the Boxmgmt CLI. An authenticated malicious user with boxmgmt privileges may potentially exploit this vulnerability to read RPA files. Note that files that require root…
ModificadaAlta (8.8)1.5%—EMC RecoverpointEMC Recoverpoint FOR Virtual Machines29/5/201817/6/2026
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in plain-text into the RecoverPoint log file. An authenticated malicious user with access to the RecoverPoint log files may obtain the exposed LDAP password to use it in…
ModificadaCrítica (9.8)42%💥 ExploitEMC RecoverpointEMC Recoverpoint FOR Virtual Machines29/5/201817/6/2026
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with root privilege.
ModificadaCrítica (9.8)1.1%—Simplemachines Simple Machines Forum24/4/201817/6/2026
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.
ModificadaCrítica (9.8)8.6%—Indusoft WEB StudioIndustrial-software Intouch Machine Edition 201718/4/201817/6/2026
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.
ModificadaMedia (6.5)1.3%—Luna Cpap Machine Firmware17/4/201817/6/2026
BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which may allow an authenticated attacker to crash the CPAP's Wi-Fi module resulting in a denial-of-service condition.
ModificadaAlta (7.8)3.1%💥 ExploitNomachineMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 828/2/201817/6/2026
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8 and 10.
ModificadaMedia (6.7)6.3%💥 ExploitDell EMC RecoverpointDell EMC Recoverpoint FOR Virtual Machines3/2/201817/6/2026
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Admin CLI may allow a malicious user with admin privileges to escape from the restricted shell to an interactive…
ModificadaMedia (6.7)1.1%—Dell EMC RecoverpointDell EMC Recoverpoint FOR Virtual Machines3/2/201817/6/2026
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Boxmgmt CLI may allow a malicious user with boxmgmt privileges to bypass Boxmgmt CLI and run arbitrary commands…
ModificadaAlta (8.2)1.7%—Ethereum Virtual Machine19/1/201817/6/2026
An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read leading to memory disclosure or denial of service. An attacker can create/send malicious a…
ModificadaMedia (5.6)94%💥 ExploitIntel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaMedia (6.1)0.64%—Wso2 Application ServerWso2 Business Process ServerWso2 Business Rules ServerWso2 Complex Event Processor+44/10/201717/6/2026
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
ModificadaMedia (4.8)3.8%💥 ExploitWso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+1321/9/201717/6/2026
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
ModificadaAlta (8.8)3.9%💥 ExploitNomachine29/8/201717/6/2026
An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files.
ModificadaAlta (8.8)2.4%—Schneider-electric Somachine7/6/201717/6/2026
A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.
ModificadaAlta (7.3)0.39%—Schneider-electric Somachine Hvac7/6/201717/6/2026
A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schneider Electric's SoMachine HVAC v2.1.0 for Modicon M171/M172 Controller.
ModificadaCrítica (9.8)1.3%—Schneider-electric Modicon Tm221ce16r FirmwareSchneider-electric Somachine6/4/201717/6/2026
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC…
ModificadaBaja (3.3)0.40%—Projectatomic Oci-register-machine29/3/201717/6/2026
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.
ModificadaAlta (7.5)1.6%—Dell Recoverpoint FOR Virtual MachinesEMC Recoverpoint21/3/201710/7/2026
EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.
ModificadaAlta (7.4)0.97%—Siemens Sinumerik Integrate Access Mymachine/ethernetSiemens Sinumerik Integrate Operate ClientSiemens Sinumerik Operate1/3/201717/6/2026
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.
ModificadaAlta (8.8)1.5%—Simplemachines Simple Machines Forum9/2/201717/6/2026
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
ModificadaCrítica (9.8)1.6%—Simplemachines Simple Machines Forum9/2/201717/6/2026
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
ModificadaMedia (6.7)0.89%—Dell Recoverpoint FOR Virtual MachinesEMC Recoverpoint3/2/201710/7/2026
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.
Orbitaley — Vulnerabilidades