Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
512 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.88% | — | Siemens JT Open ToolkitSiemens JT Utilities | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains a use after free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in… | |
| Modificada | Alta (7.8) | 0.90% | — | Siemens JT Open ToolkitSiemens JT Utilities | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to stack based buffer overflow while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the… | |
| Modificada | Baja (3.3) | 0.55% | — | Siemens JT Open ToolkitSiemens JT Utilities | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker could leverage this vulnerability to leak… | |
| Modificada | Alta (7.8) | 0.84% | — | Siemens JT Open ToolkitSiemens JT Utilities | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the… | |
| Modificada | Alta (7.8) | 1.6% | — | Siemens JT Open ToolkitSiemens JT UtilitiesSiemens Jt2goSiemens Solid Edge+1 | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versions < V2023). The Jt1001.dll contains a use-after-free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage this vulnerability… | |
| Modificada | Alta (7.8) | 1.6% | — | Siemens JT Open ToolkitSiemens JT UtilitiesSiemens Jt2goSiemens Solid Edge+1 | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versions < V2023). The Jt1001.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute… | |
| Modificada | Media (6.6) | 0.57% | — | Crypto API Toolkit FOR Intel SGX | 17/11/2021 | 17/6/2026 | Time-of-check time-of-use vulnerability in the Crypto API Toolkit for Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Distribution OF Openvino Toolkit | 17/11/2021 | 17/6/2026 | Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Oneapi Rendering Toolkit | 17/11/2021 | 17/6/2026 | Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 1.3% | — | Softing Datafeed OPC SuiteSofting EdgeconnectorSofting OPCSofting Secure Integration Server+3 | 10/11/2021 | 17/6/2026 | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted. | |
| Modificada | Alta (7.5) | 1.5% | — | Softing Smartlink Hw-dpSofting Uatoolkit Embedded | 10/11/2021 | 17/6/2026 | An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type… | |
| Analizada | Media (6.5) | 0.85% | — | Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+26 | 26/10/2021 | 17/6/2026 | A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition. | |
| Analizada | Alta (8.1) | 0.88% | — | Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+26 | 26/10/2021 | 17/6/2026 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite. | |
| Analizada | Alta (7.5) | 2.7% | — | Wago 750-8202 FirmwareWago 750-8203 FirmwareWago 750-8204 FirmwareWago 750-8206 Firmware+11 | 26/10/2021 | 17/6/2026 | In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC. | |
| Modificada | Media (6.1) | 2.4% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 13/10/2021 | 17/6/2026 | XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user. User interaction is required to exploit this vulnerability in that the victim will… | |
| Modificada | Alta (7.8) | 5.8% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 4/10/2021 | 17/6/2026 | XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a specially-crafted .cpp file. | |
| Modificada | Media (5.5) | 2.3% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 29/9/2021 | 17/6/2026 | XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a… | |
| Modificada | Alta (7.8) | 5.4% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 1/9/2021 | 17/6/2026 | XMP Toolkit SDK version 2020.1 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file. | |
| Modificada | Alta (7.8) | 2.7% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 1/9/2021 | 17/6/2026 | XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.5) | 1.9% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 1/9/2021 | 17/6/2026 | XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file. | |
| Modificada | Baja (3.3) | 0.62% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 1/9/2021 | 17/6/2026 | XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local application denial of service in the context of the current user. | |
| Modificada | Alta (7.3) | 4.4% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 1/9/2021 | 17/6/2026 | XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file. | |
| Modificada | Alta (7.8) | 2.7% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 1/9/2021 | 17/6/2026 | XMP Toolkit SDK versions 2020.1 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Modificada | Media (5.5) | 3.7% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 1/9/2021 | 17/6/2026 | XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in local application denial of service in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file. | |
| Modificada | Baja (3.3) | 2.0% | — | Adobe XMP Toolkit Software Development KITDebian Linux | 1/9/2021 | 17/6/2026 | XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a… |