Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.37% | — | Fabulatech Webcam FOR Remote Desktop | 6/3/2023 | 17/6/2026 | A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This issue affects some unknown processing in the library ftwebcam.sys of the component Global Variable Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host.… | |
| Modificada | Media (5.5) | 0.37% | — | Fabulatech Webcam FOR Remote Desktop | 6/3/2023 | 17/6/2026 | A vulnerability has been found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This vulnerability affects the function 0x222010/0x222018 in the library ftwebcam.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The… | |
| Modificada | Crítica (9.8) | 66% | 💥 Exploit | Unifiedremote Unified Remote | 6/2/2023 | 17/6/2026 | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's… | |
| Modificada | Alta (7.8) | 0.19% | — | Talend Remote Engine GEN 2 | 3/2/2023 | 9/7/2026 | All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or later and use it in place of the previous version. Talend Remote Engine Gen 1 and Talend Cloud Engine for Design are not impacted. This XXE… | |
| Modificada | Alta (7.8) | 0.37% | — | Mremoteng | 2/2/2023 | 17/6/2026 | An issue in mRemoteNG v1.76.20 allows attackers to escalate privileges via a crafted executable file. NOTE: third parties were unable to reproduce any scenario in which the claimed access of BUILTIN\Users:(M) is present. | |
| Modificada | Baja (3.3) | 0.23% | — | Devolutions Remote Desktop Manager | 26/1/2023 | 17/6/2026 | The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk. | |
| Modificada | Crítica (9.8) | 0.79% | — | Remoteclinic Remote Clinic | 20/1/2023 | 17/6/2026 | SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parameter to /medicines/profile.php. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,… | |
| Modificada | Alta (7.5) | 0.47% | — | Devolutions Remote Desktop Manager | 26/12/2022 | 17/6/2026 | Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded. | |
| Modificada | Alta (8.8) | 1.0% | — | Devolutions Remote Desktop Manager | 21/12/2022 | 17/6/2026 | Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malicious user to access the application. | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft PowershellMicrosoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 11+8 | 13/12/2022 | 17/6/2026 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 0.59% | — | Devolutions Remote Desktop Manager | 12/12/2022 | 17/6/2026 | Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoof a privileged account. | |
| Modificada | Alta (7.5) | 0.91% | — | Cybozu Remote Service | 7/12/2022 | 17/6/2026 | Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a denial-of-service (DoS) condition. | |
| Modificada | Alta (8.1) | 2.1% | — | Parallels Remote Application Server | 23/11/2022 | 17/6/2026 | The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header. | |
| Modificada | Alta (7.5) | 1.0% | — | Etictelecom Remote Access Server Firmware | 10/11/2022 | 17/6/2026 | All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory traversal through several different methods. This could allow an attacker to read sensitive files from the server, including SSH private keys, passwords, scripts, python… | |
| Modificada | Crítica (10) | 0.54% | — | Etictelecom Remote Access Server Firmware | 10/11/2022 | 17/6/2026 | All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful existing files on the filesystem, fill the hard disk to full capacity, or compromise… | |
| Modificada | Crítica (10) | 0.31% | — | Etictelecom Remote Access Server Firmware | 10/11/2022 | 17/6/2026 | All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device. | |
| Modificada | Media (6.5) | 0.48% | — | Devolutions ServerDevolutions Remote Desktop Manager | 1/11/2022 | 17/6/2026 | Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager… | |
| Modificada | Alta (7.5) | 0.59% | — | Devolutions Remote Desktop Manager | 1/11/2022 | 17/6/2026 | Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data. This issue affects : Remote Desktop Manager 2022.3.7 and prior versions. | |
| Modificada | Alta (7) | 0.16% | — | Devolutions Remote Desktop Manager | 13/9/2022 | 17/6/2026 | Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypass the application lock. This issue affects: Devolutions Remote Desktop Manager version 2022.2.14 and prior versions. | |
| Modificada | Crítica (9.8) | 2.3% | — | Openremote | 6/9/2022 | 17/6/2026 | An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule. | |
| Modificada | Alta (7.5) | 0.51% | — | Visam Vbase Web-remote | 27/7/2022 | 17/6/2026 | VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. | |
| Modificada | Media (6.1) | 0.47% | — | Visam Vbase Web-remote | 27/7/2022 | 17/6/2026 | VISAM VBASE version 11.6.0.6 does not neutralize or incorrectly neutralizes user-controllable input before the data is placed in output used as a public-facing webpage. | |
| Modificada | Alta (7.5) | 0.80% | — | Visam Vbase Web-remote | 27/7/2022 | 17/6/2026 | VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing. | |
| Modificada | Alta (7.5) | 0.89% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+15 | 11/7/2022 | 17/6/2026 | In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected. |