Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.59% | — | Omron NS Series System Program FirmwareOmron Ns10 HMI TerminalOmron Ns12 HMI TerminalOmron Ns15 HMI Terminal+2 | 24/7/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (7.5) | 3.5% | — | Hans Alshoff Minalic | 20/6/2014 | 16/6/2026 | Multiple stack-based buffer overflows in MinaliC 2.0.0 allow remote attackers to execute arbitrary code via a (1) session_id cookie in a request to the get_cookie_value function in response.c, (2) directory name in a request to the add_default_file function in response.c, or (3) file name in a request to the… | |
| Modificada | Baja (3.5) | 2.2% | — | Gnome-terminalOpensuseOracle Solaris | 21/5/2014 | 16/6/2026 | The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demonstrated by a file containing the string "\033[100000000000000000@". | |
| Modificada | Alta (7.5) | 1.3% | — | SAP Adminadapter | 10/4/2014 | 17/6/2026 | Unspecified vulnerability in SAP adminadapter allows remote attackers to read or write to arbitrary files via unknown vectors. | |
| Modificada | Alta (9) | 2.6% | — | Enea OSEEmerson DL 8000 Remote Terminal UnitEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the… | |
| Modificada | Alta (10) | 3.3% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson DL 8000 Remote Terminal UnitEmerson ROC 800 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device… | |
| Modificada | Alta (10) | 4.9% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal UnitEmerson DL 8000 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service. | |
| Modificada | Alta (10) | 5.0% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal UnitEmerson DL 8000 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.5% | — | Synel Sy-780/a Time & Attendance Terminal | 9/7/2012 | 16/6/2026 | The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network traffic to port (1) 1641, (2) 3734, or (3) 3735. | |
| Modificada | Alta (7.1) | 1.2% | — | Innominate Mguard Firmware | 19/6/2012 | 16/6/2026 | The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW-103060 and BD before BD-211010, mGuard PCI, mGuard blade, and EAGLE mGuard appliances with software before 7.5.0 do not use a sufficient source of entropy for private keys, which makes it easier for… | |
| Modificada | Media (6.8) | 0.59% | — | Typo3 Terminal | 14/2/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Baja (3.5) | 0.85% | — | Typo3 Terminal | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 0.98% | — | Apple TerminalApple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulnerabilities. | |
| Modificada | Media (6.8) | 4.5% | 💥 Exploit | Erick Woods Terminal Server Client | 7/2/2011 | 16/6/2026 | Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allow user-assisted remote attackers to execute arbitrary code via a .RDP file with a long (1) username, (2) password, or (3) domain argument. NOTE: the… | |
| Modificada | Media (6.8) | 5.2% | 💥 Exploit | Erick Woods Terminal Server Client | 7/2/2011 | 16/6/2026 | Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a .RDP file with a long hostname argument. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Vollmar COM Seminar | 4/12/2009 | 16/6/2026 | SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Projektseminar Proservice WWU Virtual Civil Services | 17/6/2009 | 16/6/2026 | SQL injection vulnerability in the Virtual Civil Services (civserv) extension 4.3.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.9) | 0.35% | — | Jonas Smedegaard Sdm-terminal | 8/12/2008 | 16/6/2026 | sdm-login in sdm-terminal 0.4.0b allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sdm.autologin.once temporary file. | |
| Modificada | Media (6.9) | 0.34% | — | Mohammed Sameer Multi-gnome-terminal | 18/11/2008 | 16/6/2026 | mgt-helper in multi-gnome-terminal 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.debug or (2) /tmp/*.env temporary file. | |
| Modificada | Media (4.8) | 1.2% | — | Ltsp Linux Terminal Server Project | 29/4/2008 | 16/6/2026 | ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which allows remote attackers to connect to this server via TCP port 6006 (aka display :6). | |
| Modificada | Alta (7.8) | 2.2% | — | Os-cillation Xfce Terminal | 15/7/2007 | 16/6/2026 | The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the "Open Link" functionality. | |
| Modificada | Alta (7.5) | 9.4% | — | Microsoft Terminal Server | 11/5/2007 | 16/6/2026 | The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0… | |
| Modificada | Alta (7.5) | 1.4% | — | Mina Ajans Script | 7/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in Mina Ajans Script allows remote attackers to execute arbitrary PHP code via a URL in the syf parameter to an unspecified PHP script. | |
| Modificada | Alta (10) | 9.4% | — | Microsoft Terminal Server | 31/8/2006 | 16/6/2026 | Microsoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client Connection Manager wizard" options, allows local users to execute arbitrary code by forcing an Explorer error. NOTE: a third-party researcher has stated that the options… | |
| Modificada | Alta (10) | 2.5% | — | Ak-systems Windows Terminal | 23/8/2006 | 16/6/2026 | VNC server on the AK-Systems Windows Terminal 1.2.5 ExVLP is not password protected, which allows remote attackers to login and view RDP or Citrix sessions. |