Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Integrated Dell Remote Access Controller 8 Firmware | 21/4/2022 | 17/6/2026 | Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to cause resource exhaustion in the webserver, resulting in a denial of service condition. | |
| Modificada | Media (5.3) | 2.1% | — | Zohocorp Manageengine Remote Access Plus | 16/4/2022 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details. | |
| Modificada | Media (5.3) | 2.1% | — | Zohocorp Manageengine Remote Access Plus | 16/4/2022 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator). | |
| Modificada | Crítica (9.8) | 2.4% | — | ATT XmillSchneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/4/2022 | 17/6/2026 | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or… | |
| Modificada | Alta (7.8) | 26% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 13/4/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software.… | |
| Modificada | Alta (7.8) | 0.61% | — | Ivanti DSM Remote | 11/4/2022 | 17/6/2026 | Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges. | |
| Modificada | Alta (7.5) | 1.5% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+14 | 7/4/2022 | 17/6/2026 | A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. | |
| Modificada | Alta (7.5) | 1.3% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed. | |
| Modificada | Alta (8.1) | 1.1% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+14 | 7/4/2022 | 17/6/2026 | A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. | |
| Modificada | Alta (7.1) | 0.89% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed,… | |
| Modificada | Media (6.5) | 1.0% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. | |
| Modificada | Media (5.3) | 2.4% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 11Microsoft Windows 7+8 | 9/3/2022 | 17/6/2026 | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 0.25% | — | Rdpsoft Remote Desktop Commander Suite Agent | 3/3/2022 | 17/6/2026 | Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level. | |
| Modificada | Crítica (9.8) | 4.8% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 18/2/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. | |
| Modificada | Alta (7.5) | 4.7% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 18/2/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. | |
| Modificada | Media (6.5) | 3.3% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 18/2/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element. | |
| Modificada | Alta (7.8) | 0.41% | — | Trigonesoft Remote System Monitor | 17/2/2022 | 17/6/2026 | TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges. | |
| Modificada | Crítica (9.8) | 34% | 💥 PoC | Libexpat Project LibexpatDebian LinuxOracle Http ServerOracle ZFS Storage Appliance KIT+1 | 16/2/2022 | 17/6/2026 | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. | |
| Modificada | Crítica (9.8) | 5.0% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+2 | 16/2/2022 | 17/6/2026 | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. | |
| Modificada | Media (6.1) | 5.3% | 💥 Exploit | Siemens Sinema Remote Connect Server | 9/2/2022 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there by leading to phishing attacks. | |
| Modificada | Alta (7.5) | 4.0% | 💥 PoC | Libexpat Project LibexpatTenable NessusOracle Communications Metasolv SolutionDebian Linux+2 | 26/1/2022 | 17/6/2026 | Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. | |
| Modificada | Alta (8.1) | 1.1% | — | Integrated Dell Remote Access Controller 9 Firmware | 25/1/2022 | 17/6/2026 | iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC. | |
| Modificada | Alta (7.2) | 2.2% | — | Integrated Dell Remote Access Controller 8 FirmwareIntegrated Dell Remote Access Controller 9 Firmware | 25/1/2022 | 17/6/2026 | iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the iDRAC operating system. | |
| Modificada | Media (5.3) | 4.2% | — | Integrated Dell Remote Access Controller 8 Firmware | 25/1/2022 | 17/6/2026 | Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to deny access to the iDRAC webserver. | |
| Modificada | Crítica (9.8) | 4.6% | 💥 PoC | Libexpat Project LibexpatNetapp Clustered Data OntapNetapp Oncommand Workflow AutomationTenable Nessus+3 | 24/1/2022 | 17/6/2026 | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES. |