Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.6%—Integrated Dell Remote Access Controller 8 Firmware21/4/202217/6/2026
Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to cause resource exhaustion in the webserver, resulting in a denial of service condition.
ModificadaMedia (5.3)2.1%—Zohocorp Manageengine Remote Access Plus16/4/202217/6/2026
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
ModificadaMedia (5.3)2.1%—Zohocorp Manageengine Remote Access Plus16/4/202217/6/2026
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
ModificadaCrítica (9.8)2.4%—ATT XmillSchneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect14/4/202217/6/2026
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or…
ModificadaAlta (7.8)26%—Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect13/4/202217/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software.…
ModificadaAlta (7.8)0.61%—Ivanti DSM Remote11/4/202217/6/2026
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
ModificadaAlta (7.5)1.5%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+147/4/202217/6/2026
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
ModificadaAlta (7.5)1.3%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
ModificadaAlta (8.1)1.1%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+147/4/202217/6/2026
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.
ModificadaAlta (7.1)0.89%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed,…
ModificadaMedia (6.5)1.0%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
ModificadaMedia (5.3)2.4%—Microsoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 11Microsoft Windows 7+89/3/202217/6/2026
Remote Desktop Protocol Client Information Disclosure Vulnerability
ModificadaAlta (7.8)0.25%—Rdpsoft Remote Desktop Commander Suite Agent3/3/202217/6/2026
Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.
ModificadaCrítica (9.8)4.8%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
ModificadaAlta (7.5)4.7%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
ModificadaMedia (6.5)3.3%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
ModificadaAlta (7.8)0.41%—Trigonesoft Remote System Monitor17/2/202217/6/2026
TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.
ModificadaCrítica (9.8)34%💥 PoCLibexpat Project LibexpatDebian LinuxOracle Http ServerOracle ZFS Storage Appliance KIT+116/2/202217/6/2026
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
ModificadaCrítica (9.8)5.0%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+216/2/202217/6/2026
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
ModificadaMedia (6.1)5.3%💥 ExploitSiemens Sinema Remote Connect Server9/2/202217/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks.
ModificadaAlta (7.5)4.0%💥 PoCLibexpat Project LibexpatTenable NessusOracle Communications Metasolv SolutionDebian Linux+226/1/202217/6/2026
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
ModificadaAlta (8.1)1.1%—Integrated Dell Remote Access Controller 9 Firmware25/1/202217/6/2026
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC.
ModificadaAlta (7.2)2.2%—Integrated Dell Remote Access Controller 8 FirmwareIntegrated Dell Remote Access Controller 9 Firmware25/1/202217/6/2026
iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system.
ModificadaMedia (5.3)4.2%—Integrated Dell Remote Access Controller 8 Firmware25/1/202217/6/2026
Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver.
ModificadaCrítica (9.8)4.6%💥 PoCLibexpat Project LibexpatNetapp Clustered Data OntapNetapp Oncommand Workflow AutomationTenable Nessus+324/1/202217/6/2026
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
Orbitaley — Vulnerabilidades