Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

390 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.0%—Uvnc UltravncSiemens Sinumerik Access Mymachine/p2pSiemens Sinumerik PCU Base Win10 Software/ipcSiemens Sinumerik PCU Base Win7 Software/ipc5/3/201917/6/2026
UltraVNC revision 1198 contains multiple memory leaks (CWE-655) in VNC client code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appears to be exploitable via network…
ModificadaCrítica (9.8)4.4%—Uvnc UltravncSiemens Sinumerik Access Mymachine/p2pSiemens Sinumerik PCU Base Win10 Software/ipcSiemens Sinumerik PCU Base Win7 Software/ipc5/3/201917/6/2026
UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
ModificadaCrítica (9.8)2.9%—Uvnc Ultravnc5/3/201917/6/2026
UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
ModificadaAlta (7.8)0.40%—Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+5524/1/201917/6/2026
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
ModificadaCrítica (9.8)87%💥 ExploitWestern Digital MY Cloud Wdbctl0020hwt FirmwareWestern Digital MY Cloud Pr4100Western Digital MY Cloud Pr2100 FirmwareWestern Digital MY Cloud Mirror GEN 2 Firmware+818/9/201817/6/2026
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an…
ModificadaAlta (7.5)0.88%—Thomsonreuters Ultratax CS26/7/201817/6/2026
Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique directories…
ModificadaAlta (7.5)0.87%—Thomsonreuters Ultratax CS 201726/7/201817/6/2026
Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors. The…
ModificadaAlta (7.8)1.7%—Ezbsystems Ultraiso24/4/201817/6/2026
A buffer overflow vulnerability exists in the ISO parsing functionality of EZB Systems UltraISO 9.6.6.3300. A specially crafted .ISO file can cause a vulnerability resulting in potential code execution. An attacker can provide a specific .ISO file to trigger this vulnerability.
ModificadaAlta (7.4)1.00%—Swhouse Istar Ultra Firmware31/12/201717/6/2026
A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the…
ModificadaMedia (6.5)1.2%—Cisco Ultra Services Platform17/8/201717/6/2026
A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote attacker to acquire sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this…
ModificadaAlta (7.5)1.7%—Cisco Ultra Services Framework17/8/201717/6/2026
A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by browsing to a specific URL of an…
ModificadaMedia (6.3)0.34%—NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+237/8/201717/6/2026
A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device is configured in security enabled…
ModificadaMedia (6)0.26%—NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+267/8/201717/6/2026
An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is…
ModificadaCrítica (9.8)4.2%—Cisco Ultra Services Framework Staging Server6/7/201717/6/2026
A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. An attacker could exploit this vulnerability by crafting CLI command…
ModificadaCrítica (9.1)1.6%—Cisco Ultra Services Framework6/7/201717/6/2026
A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. The vulnerability is due to an insecure default configuration of the Apache ZooKeeper service used by the affected software. An…
ModificadaCrítica (9.8)1.3%—Cisco Ultra Services Framework6/7/201717/6/2026
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in an affected system. The vulnerability exists because the affected software logs…
ModificadaCrítica (9.8)1.5%—Cisco Ultra Services Framework6/7/201717/6/2026
A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The vulnerability is due to the absence of validation checks for the…
ModificadaMedia (5.5)0.31%—Cisco Ultra Services Platform13/6/201717/6/2026
A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive information. More Information: CSCvd29398. Known Affected Releases: 21.0.v0.65839.
ModificadaMedia (5.5)0.27%—Cisco Ultra Services Platform13/6/201717/6/2026
A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive data (cleartext credentials) on an affected system. More Information: CSCvd29355. Known Affected Releases: 21.0.v0.65839.
ModificadaAlta (8.8)2.3%—Cisco Ultra Services Framework Element Manager13/6/201717/6/2026
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker to log in to the device with the privileges of the root user, aka an Insecure Default Account Information Vulnerability. More Information: CSCvd85710. Known Affected Releases: 21.0.v0.65839.
ModificadaAlta (8.8)1.5%—Cisco Ultra Services Framework Element Manager13/6/201717/6/2026
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on the system, aka an Insecure Default Password Vulnerability. More Information: CSCvc76695. Known…
ModificadaAlta (8.8)1.5%—Cisco Ultra Services Framework Element Manager13/6/201717/6/2026
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76699. Known Affected Releases:…
ModificadaAlta (8.8)1.5%—Cisco Ultra Services Framework Staging Server13/6/201717/6/2026
A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76681. Known Affected Releases: 21.0.0.
ModificadaAlta (7.5)2.6%—Cisco Ultra Services Framework13/6/201717/6/2026
A vulnerability in the AutoVNF VNFStagingView class of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to execute a relative path traversal attack, enabling an attacker to read sensitive files on the system. More Information: CSCvc76662. Known Affected Releases: 21.0.0.
ModificadaAlta (7.5)1.4%—Cisco Ultra Services Framework13/6/201717/6/2026
A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system. More Information: CSCvc76652. Known Affected Releases: 21.0.0.