Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.32% | — | Thalesgroup Safenet Authentication Service Remote Desktop Gateway | 19/1/2022 | 17/6/2026 | A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed. | |
| Modificada | Alta (8.8) | 2.8% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Alta (8.8) | 2.8% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Alta (8.8) | 2.6% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Crítica (9.8) | 3.4% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Crítica (9.8) | 3.4% | — | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server | 10/1/2022 | 17/6/2026 | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Crítica (9.8) | 4.8% | 💥 PoC | Libexpat Project LibexpatTenable NessusSiemens Sinema Remote Connect ServerDebian Linux | 10/1/2022 | 17/6/2026 | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | |
| Modificada | Alta (7.8) | 3.8% | 💥 PoC | Libexpat Project LibexpatNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Baseboard Management Controller+4 | 6/1/2022 | 17/6/2026 | In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize. | |
| Modificada | Alta (8.8) | 4.2% | 💥 PoC | Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server+4 | 1/1/2022 | 17/6/2026 | In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). | |
| Modificada | Alta (7.5) | 0.59% | — | Apple Remote Desktop | 23/12/2021 | 17/6/2026 | A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker may be able to capture cleartext passwords. | |
| Modificada | Alta (7.1) | 0.27% | — | Parallels Remote Application Server | 17/12/2021 | 17/6/2026 | Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be compromised if an attacker is able to… | |
| Modificada | Media (5.4) | 0.46% | — | Socomec Remote View PRO Firmware | 15/12/2021 | 17/6/2026 | An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Event Log. | |
| Modificada | Alta (8.8) | 1.1% | — | Socomec Remote View PRO Firmware | 15/12/2021 | 17/6/2026 | An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files. | |
| Modificada | Alta (7.3) | 1.2% | — | Dreamreport Remote Connector | 8/12/2021 | 17/6/2026 | A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2.16900.0. A specially-crafted command injection can lead to elevated capabilities. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.43% | — | Zohocorp Manageengine Remote Access Plus | 17/11/2021 | 17/6/2026 | Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account. | |
| Modificada | Alta (7.8) | 0.39% | — | Zohocorp Manageengine Remote Access Plus | 17/11/2021 | 17/6/2026 | Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation,… | |
| Modificada | Alta (8.8) | 0.66% | — | Zoho Manageengine Remote Access Plus Server | 17/11/2021 | 17/6/2026 | Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive… | |
| Modificada | Media (6.5) | 7.0% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 11Microsoft Windows 7+7 | 10/11/2021 | 19/8/2026 | Remote Desktop Protocol Client Information Disclosure Vulnerability | |
| Modificada | Media (6.1) | 1.1% | — | Remoteclinic Remote Clinic | 5/11/2021 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in Remote Clinic v2.0 in (1) patients/register-patient.php via the (a) Contact, (b) Email, (c) Weight, (d) Profession, (e) ref_contact, (f) address, (g) gender, (h) age, and (i) serial parameters; in (2) patients/edit-patient.php via the (a) Contact, (b)… | |
| Modificada | Alta (8.8) | 1.8% | — | Devolutions Remote Desktop Manager | 18/10/2021 | 17/6/2026 | An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell. | |
| Modificada | Alta (7.5) | 5.3% | — | StrongswanDebian LinuxFedoraproject FedoraSiemens Sinema Remote Connect Server+21 | 18/10/2021 | 17/6/2026 | The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but… | |
| Modificada | Media (6.1) | 0.75% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.1) | 0.82% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors. |