Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+8 | 4/10/2021 | 17/6/2026 | Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server… | |
| Modificada | Crítica (9.8) | 1.2% | — | Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+8 | 4/10/2021 | 17/6/2026 | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system. | |
| Modificada | Media (6.1) | 0.63% | — | Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 Firmware | 4/10/2021 | 17/6/2026 | The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL. | |
| Modificada | Alta (7.5) | 0.60% | — | Bosch Rexroth Indramotion XLC FirmwareBosch Rexroth Indramotion MLC Firmware | 4/10/2021 | 17/6/2026 | The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Media (5.3) | 0.85% | — | Redhat Wildfly ElytronRedhat Build OF QuarkusRedhat Codeready StudioRedhat Data Grid+9 | 5/8/2021 | 17/6/2026 | A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. | |
| Modificada | Alta (8.8) | 0.49% | — | Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Aviotec FirmwareBosch Cpp7 Firmware+3 | 5/8/2021 | 17/6/2026 | A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or opening a malicious website while being logged in into… | |
| Modificada | Media (6.5) | 2.0% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesOracle ZFS Storage Appliance KITNetapp Active IQ Unified Manager+15 | 9/7/2021 | 17/6/2026 | A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. | |
| Modificada | Crítica (9.8) | 1.1% | — | Ibos | 24/6/2021 | 17/6/2026 | In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php. | |
| Modificada | Alta (8.8) | 2.7% | — | Ibos | 24/6/2021 | 17/6/2026 | In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability. | |
| Modificada | Media (6.1) | 0.69% | — | Ibos | 24/6/2021 | 17/6/2026 | In IBOS 4.5.4 the email function has a cross site scripting (XSS) vulnerability in emailbody[content] parameter. | |
| Modificada | Media (5.9) | 0.47% | — | Bosch B426 Firmware | 18/6/2021 | 17/6/2026 | When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021. | |
| Modificada | Alta (8.8) | 0.84% | — | Bosch B426 FirmwareBosch B426-cn FirmwareBosch B429-cn FirmwareBosch B426-m Firmware | 18/6/2021 | 17/6/2026 | This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which… | |
| Modificada | Media (6.1) | 0.56% | — | Bosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 FirmwareBosch Cpp13 Firmware | 9/6/2021 | 17/6/2026 | An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected. | |
| Modificada | Crítica (9.8) | 0.86% | — | Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+1 | 9/6/2021 | 17/6/2026 | In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs. | |
| Modificada | Media (4.9) | 0.83% | — | Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+1 | 9/6/2021 | 17/6/2026 | An authenticated attacker with administrator rights Bosch IP cameras can call an URL with an invalid parameter that causes the camera to become unresponsive for a few seconds and cause a Denial of Service (DoS). | |
| Modificada | Media (6.1) | 0.56% | — | Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+1 | 9/6/2021 | 17/6/2026 | An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user. | |
| Modificada | Crítica (9.1) | 1.4% | — | Bosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware | 9/6/2021 | 17/6/2026 | A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are… | |
| Modificada | Media (5.9) | 1.1% | — | Redhat Jboss-remoting | 2/6/2021 | 17/6/2026 | A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected messages of a successful EJB client request, but omitting the ACK messages, or just tamper with… | |
| Modificada | Media (5.9) | 2.2% | — | Redhat XnioRedhat Jboss BrmsRedhat Jboss Data GridRedhat Jboss Data Virtualization+10 | 2/6/2021 | 17/6/2026 | A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final. | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Jboss Enterprise Application PlatformRedhat Wildfly | 2/6/2021 | 17/6/2026 | It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any… | |
| Modificada | Media (4.4) | 0.29% | — | Redhat Jboss A-mq | 1/6/2021 | 17/6/2026 | A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ 7 are vulnerable. | |
| Modificada | Alta (7.8) | 2.0% | — | Xmlsoft XmllintDebian LinuxFedoraproject FedoraRedhat Jboss Core Services+5 | 1/6/2021 | 17/6/2026 | There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability. | |
| Modificada | Alta (8.8) | 2.0% | — | PostgresqlRedhat Jboss Enterprise Application PlatformRedhat Software CollectionsRedhat Enterprise Linux | 1/6/2021 | 17/6/2026 | A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The highest threat from this vulnerability is to… | |
| Modificada | Alta (7.5) | 2.7% | — | OpenldapRedhat Jboss Core ServicesRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Server+3 | 28/5/2021 | 17/6/2026 | A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability. |