Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.0% | — | Uvnc UltravncSiemens Sinumerik Access Mymachine/p2pSiemens Sinumerik PCU Base Win10 Software/ipcSiemens Sinumerik PCU Base Win7 Software/ipc | 5/3/2019 | 17/6/2026 | UltraVNC revision 1198 contains multiple memory leaks (CWE-655) in VNC client code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appears to be exploitable via network… | |
| Modificada | Crítica (9.8) | 4.4% | — | Uvnc UltravncSiemens Sinumerik Access Mymachine/p2pSiemens Sinumerik PCU Base Win10 Software/ipcSiemens Sinumerik PCU Base Win7 Software/ipc | 5/3/2019 | 17/6/2026 | UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199. | |
| Modificada | Crítica (9.8) | 2.9% | — | Uvnc Ultravnc | 5/3/2019 | 17/6/2026 | UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199. | |
| Modificada | Alta (7.8) | 0.40% | — | Lenovo Synaptics Thinkpad Ultranav DriverLenovo Thinkpad Helix FirmwareLenovo Thiankpad L430 FirmwareLenovo Thiankpad L530 Firmware+55 | 24/1/2019 | 17/6/2026 | In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Western Digital MY Cloud Wdbctl0020hwt FirmwareWestern Digital MY Cloud Pr4100Western Digital MY Cloud Pr2100 FirmwareWestern Digital MY Cloud Mirror GEN 2 Firmware+8 | 18/9/2018 | 17/6/2026 | It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an… | |
| Modificada | Alta (7.5) | 0.88% | — | Thomsonreuters Ultratax CS | 26/7/2018 | 17/6/2026 | Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique directories… | |
| Modificada | Alta (7.5) | 0.87% | — | Thomsonreuters Ultratax CS 2017 | 26/7/2018 | 17/6/2026 | Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors. The… | |
| Modificada | Alta (7.8) | 1.7% | — | Ezbsystems Ultraiso | 24/4/2018 | 17/6/2026 | A buffer overflow vulnerability exists in the ISO parsing functionality of EZB Systems UltraISO 9.6.6.3300. A specially crafted .ISO file can cause a vulnerability resulting in potential code execution. An attacker can provide a specific .ISO file to trigger this vulnerability. | |
| Modificada | Alta (7.4) | 1.00% | — | Swhouse Istar Ultra Firmware | 31/12/2017 | 17/6/2026 | A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the… | |
| Modificada | Media (6.5) | 1.2% | — | Cisco Ultra Services Platform | 17/8/2017 | 17/6/2026 | A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote attacker to acquire sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Ultra Services Framework | 17/8/2017 | 17/6/2026 | A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by browsing to a specific URL of an… | |
| Modificada | Media (6.3) | 0.34% | — | NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+23 | 7/8/2017 | 17/6/2026 | A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device is configured in security enabled… | |
| Modificada | Media (6) | 0.26% | — | NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+26 | 7/8/2017 | 17/6/2026 | An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is… | |
| Modificada | Crítica (9.8) | 4.2% | — | Cisco Ultra Services Framework Staging Server | 6/7/2017 | 17/6/2026 | A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. An attacker could exploit this vulnerability by crafting CLI command… | |
| Modificada | Crítica (9.1) | 1.6% | — | Cisco Ultra Services Framework | 6/7/2017 | 17/6/2026 | A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. The vulnerability is due to an insecure default configuration of the Apache ZooKeeper service used by the affected software. An… | |
| Modificada | Crítica (9.8) | 1.3% | — | Cisco Ultra Services Framework | 6/7/2017 | 17/6/2026 | A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in an affected system. The vulnerability exists because the affected software logs… | |
| Modificada | Crítica (9.8) | 1.5% | — | Cisco Ultra Services Framework | 6/7/2017 | 17/6/2026 | A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The vulnerability is due to the absence of validation checks for the… | |
| Modificada | Media (5.5) | 0.31% | — | Cisco Ultra Services Platform | 13/6/2017 | 17/6/2026 | A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive information. More Information: CSCvd29398. Known Affected Releases: 21.0.v0.65839. | |
| Modificada | Media (5.5) | 0.27% | — | Cisco Ultra Services Platform | 13/6/2017 | 17/6/2026 | A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive data (cleartext credentials) on an affected system. More Information: CSCvd29355. Known Affected Releases: 21.0.v0.65839. | |
| Modificada | Alta (8.8) | 2.3% | — | Cisco Ultra Services Framework Element Manager | 13/6/2017 | 17/6/2026 | A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker to log in to the device with the privileges of the root user, aka an Insecure Default Account Information Vulnerability. More Information: CSCvd85710. Known Affected Releases: 21.0.v0.65839. | |
| Modificada | Alta (8.8) | 1.5% | — | Cisco Ultra Services Framework Element Manager | 13/6/2017 | 17/6/2026 | A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on the system, aka an Insecure Default Password Vulnerability. More Information: CSCvc76695. Known… | |
| Modificada | Alta (8.8) | 1.5% | — | Cisco Ultra Services Framework Element Manager | 13/6/2017 | 17/6/2026 | A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76699. Known Affected Releases:… | |
| Modificada | Alta (8.8) | 1.5% | — | Cisco Ultra Services Framework Staging Server | 13/6/2017 | 17/6/2026 | A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76681. Known Affected Releases: 21.0.0. | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco Ultra Services Framework | 13/6/2017 | 17/6/2026 | A vulnerability in the AutoVNF VNFStagingView class of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to execute a relative path traversal attack, enabling an attacker to read sensitive files on the system. More Information: CSCvc76662. Known Affected Releases: 21.0.0. | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Ultra Services Framework | 13/6/2017 | 17/6/2026 | A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system. More Information: CSCvc76652. Known Affected Releases: 21.0.0. |