Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.96%—Cybozu Remote Service Manager3/8/202317/6/2026
Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition.
ModificadaAlta (7.5)0.48%💥 PoCMremoteng26/7/202317/6/2026
Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG version <= v1.76.20 and <= 1.77.3-dev loads…
ModificadaMedia (5.5)0.16%—HPE Insight Remote Support16/6/202317/6/2026
A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.
ModificadaMedia (5.5)0.25%—Teamviewer Remote14/6/202317/6/2026
An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings even though the options were locked. This can result in unwanted changes to the configuration.
AnalizadaAlta (8.8)1.3%—Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+914/6/202317/6/2026
Remote Desktop Client Remote Code Execution Vulnerability
AnalizadaMedia (6.5)1.2%—Microsoft Remote Desktop ClientMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+414/6/202317/6/2026
Windows Remote Desktop Security Feature Bypass Vulnerability
ModificadaMedia (5.5)0.36%—Fabulatech USB FOR Remote Desktop24/5/202317/6/2026
A vulnerability was found in FabulaTech USB for Remote Desktop 6.1.0.0. It has been rated as problematic. Affected by this issue is the function 0x220448/0x220420/0x22040c/0x220408 of the component IoControlCode Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The…
ModificadaMedia (5.8)0.53%—Teltonika Remote Management System22/5/202317/6/2026
Teltonika’s Remote Management System versions prior to 4.10.0 contain a virtual private network (VPN) hub feature for cross-device communication that uses OpenVPN. It connects new devices in a manner that allows the new device to communicate with all Teltonika devices connected to the VPN. The OpenVPN server also…
ModificadaAlta (8.8)1.1%—Teltonika Remote Management System22/5/202317/6/2026
Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (SSH)/web management services over the cloud proxy. A user can request a web proxy and obtain a URL in the Remote Management System cloud subdomain. This URL could be shared with…
ModificadaAlta (8.3)0.92%—Teltonika Remote Management System22/5/202317/6/2026
Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the web interface. An attacker with the MAC address and serial number of a connected device could send a maliciously crafted JSON file with an HTML object to trigger the vulnerability.…
ModificadaCrítica (9.8)1.0%—Teltonika Remote Management System22/5/202317/6/2026
Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then an attacker could register that device to themselves. This could enable…
ModificadaCrítica (9.8)0.66%—Teltonika Remote Management System22/5/202317/6/2026
Teltonika’s Remote Management System versions prior to 4.10.0 use device serial numbers and MAC addresses to identify devices from the user perspective for device claiming and from the device perspective for authentication. If an attacker obtained the serial number and MAC address of a device, they could authenticate…
ModificadaMedia (5.3)0.54%—Teltonika Remote Management System22/5/202317/6/2026
Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MAC address of a device has already been claimed, or whether the attempt to claim a…
AnalizadaMedia (5.3)1.2%—Microsoft Remote Desktop APP9/5/202317/6/2026
Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability
ModificadaMedia (6.5)0.42%—Devolutions Remote Desktop Manager25/4/202317/6/2026
Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.
ModificadaMedia (6.5)0.62%—Oracle Clinical Remote Data Capture18/4/202317/6/2026
Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture.…
AnalizadaMedia (6.5)2.1%—Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+1011/4/202317/6/2026
Remote Desktop Protocol Client Information Disclosure Vulnerability
ModificadaMedia (6.5)0.52%—Devolutions Remote Desktop Manager11/4/202317/6/2026
Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authentication via the application user interface and open entries.
ModificadaMedia (4.3)0.40%—Devolutions Remote Desktop Manager11/4/202317/6/2026
No access control for the OTP key on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.
ModificadaMedia (6.5)0.71%—Jenkins Remote-jobs-view2/4/202317/6/2026
Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (6.5)0.48%—Devolutions Remote Desktop Manager2/4/202317/6/2026
Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text.
ModificadaMedia (6.5)0.44%—Devolutions Remote Desktop Manager2/4/202317/6/2026
Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision.
ModificadaAlta (8.8)1.0%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+1123/3/202317/6/2026
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.
ModificadaMedia (6.5)1.1%—Devolutions Remote Desktop Manager10/3/202317/6/2026
Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Manager PowerShell Module 2022.3.1.5 and earlier allows an authenticated user to access sensitive data on entries that were edited using the affected submodule.
ModificadaMedia (5.5)0.37%—Fabulatech Webcam FOR Remote Desktop6/3/202317/6/2026
A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42. It has been classified as problematic. Affected is the function 0x222018 in the library ftwebcam.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has…