Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.72%—Cybozu Remote Service Manager13/10/202117/6/2026
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.
ModificadaMedia (5.3)0.99%—Cybozu Remote Service Manager13/10/202117/6/2026
HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.
ModificadaMedia (6.5)1.1%—Cybozu Remote Service Manager13/10/202117/6/2026
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.
ModificadaMedia (5.4)0.60%—Cybozu Remote Service Manager13/10/202117/6/2026
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (5.4)0.61%—Cybozu Remote Service Manager13/10/202117/6/2026
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (5.4)0.61%—Cybozu Remote Service Manager13/10/202117/6/2026
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (5.4)0.61%—Cybozu Remote Service Manager13/10/202117/6/2026
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.
ModificadaMedia (6.5)1.5%—Cybozu Remote Service Manager13/10/202117/6/2026
Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors.
ModificadaAlta (8.8)0.56%—Cybozu Remote Service Manager13/10/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.
ModificadaAlta (7.8)0.22%—Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+1012/10/202117/6/2026
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.
ModificadaCrítica (9.8)2.5%—Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+1012/10/202117/6/2026
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS.
ModificadaAlta (7.5)3.2%—Zohocorp Manageengine Remote Access Plus30/9/202117/6/2026
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
ModificadaAlta (7.5)4.7%—Zohocorp Manageengine Remote Access Plus30/9/202117/6/2026
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
ModificadaAlta (7.5)4.7%—Zohocorp Manageengine Remote Access Plus30/9/202117/6/2026
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.
ModificadaAlta (8.8)1.3%—Device42 Remote Collector17/9/202117/6/2026
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (with access to the console application) to execute arbitrary OS commands and escalate privileges.
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaAlta (7.5)65%—Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1416/9/202117/6/2026
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaMedia (4.3)0.36%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).
ModificadaMedia (4.3)0.36%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve a list of network devices a known user can manage.
ModificadaMedia (4.3)0.38%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.
ModificadaMedia (4.3)0.36%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.
ModificadaMedia (6.5)0.37%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software allows sending send-to-sleep notifications to the managed devices. An unauthenticated attacker in the same network of the affected system can abuse these notifications to cause a Denial-of-Service…
ModificadaMedia (6.5)0.39%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker in the same network of the affected system.
ModificadaAlta (7.8)0.24%—Siemens Sinema Remote Connect19/8/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privileges and execute own code on the device.
ModificadaAlta (8.8)22%—Microsoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+512/8/202110/8/2026
Remote Desktop Client Remote Code Execution Vulnerability
Orbitaley — Vulnerabilidades