Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.54% | — | Jfrog Artifactory | 19/5/2022 | 17/6/2026 | JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators. | |
| Modificada | Alta (8.8) | 2.1% | — | Jfrog Artifactory | 16/5/2022 | 17/6/2026 | JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient validation of a user-provided serialized… | |
| Modificada | Media (6.5) | 1.7% | 💥 PoC | Lmsdoctor 2 Factor Authentication | 10/5/2022 | 17/6/2026 | A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism. | |
| Modificada | Alta (7.5) | 2.3% | 💥 PoC | Lmsdoctor 2 Factor Authentication | 10/5/2022 | 9/7/2026 | LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts. | |
| Modificada | Alta (7.8) | 0.24% | — | Samsung Factorycamera | 11/4/2022 | 17/6/2026 | Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege. | |
| Modificada | Media (5.3) | 0.88% | — | Tinfoilsecurity Devise-two-factor | 11/4/2022 | 17/6/2026 | As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N) | |
| Modificada | Alta (8.8) | 2.4% | — | Rockwellautomation Factorytalk Services Platform | 1/4/2022 | 17/6/2026 | Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have… | |
| Modificada | Crítica (9.8) | 4.1% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier. | |
| Modificada | Alta (7.5) | 1.6% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 5.7% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.8% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.5% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.9% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.5% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.8% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.2% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk… | |
| Modificada | Media (5.5) | 0.26% | — | HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware | 2/3/2022 | 17/6/2026 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | |
| Modificada | Media (5.5) | 0.26% | — | HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware | 2/3/2022 | 17/6/2026 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | |
| Modificada | Media (5.5) | 0.26% | — | HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware | 2/3/2022 | 17/6/2026 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | |
| Modificada | Media (5.5) | 0.26% | — | HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware | 2/3/2022 | 17/6/2026 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | |
| Modificada | Baja (2.7) | 0.65% | — | Jfrog Artifactory | 2/3/2022 | 17/6/2026 | JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation. | |
| Modificada | Media (5.4) | 0.63% | — | Jfrog Artifactory | 2/3/2022 | 17/6/2026 | JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session. | |
| Modificada | Media (5.5) | 0.26% | — | HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware | 2/3/2022 | 17/6/2026 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | |
| Modificada | Media (5.5) | 0.26% | — | HP Probook 440 G8 FirmwareHP Prodesk 405 G6 Small Form Factor Firmware | 2/3/2022 | 17/6/2026 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. | |
| Modificada | Alta (7.8) | 0.16% | — | Rockwellautomation Factorytalk View | 24/2/2022 | 17/6/2026 | The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the… |