Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.72% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen. | |
| Modificada | Media (5.3) | 0.99% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product. | |
| Modificada | Media (6.5) | 1.1% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox. | |
| Modificada | Media (6.5) | 1.5% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.56% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.22% | — | Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+10 | 12/10/2021 | 17/6/2026 | Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system. | |
| Modificada | Crítica (9.8) | 2.5% | — | Hitachi IT Operations DirectorHitachi JOB Management Partner 1/it Desktop Management-managerHitachi JOB Management Partner 1/it Desktop Management 2-managerHitachi JOB Management Partner 1/remote Control Agent+10 | 12/10/2021 | 17/6/2026 | Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying OS. | |
| Modificada | Alta (7.5) | 3.2% | — | Zohocorp Manageengine Remote Access Plus | 30/9/2021 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key. | |
| Modificada | Alta (7.5) | 4.7% | — | Zohocorp Manageengine Remote Access Plus | 30/9/2021 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml. | |
| Modificada | Alta (7.5) | 4.7% | — | Zohocorp Manageengine Remote Access Plus | 30/9/2021 | 17/6/2026 | Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive. | |
| Modificada | Alta (8.8) | 1.3% | — | Device42 Remote Collector | 17/9/2021 | 17/6/2026 | The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows an authenticated attacker (with access to the console application) to execute arbitrary OS commands and escalate privileges. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Alta (7.5) | 65% | — | Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+14 | 16/9/2021 | 17/6/2026 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Modificada | Media (4.3) | 0.36% | — | Siemens Sinema Remote Connect Server | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa). | |
| Modificada | Media (4.3) | 0.36% | — | Siemens Sinema Remote Connect Server | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve a list of network devices a known user can manage. | |
| Modificada | Media (4.3) | 0.38% | — | Siemens Sinema Remote Connect Server | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software. | |
| Modificada | Media (4.3) | 0.36% | — | Siemens Sinema Remote Connect Server | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user. | |
| Modificada | Media (6.5) | 0.37% | — | Siemens Sinema Remote Connect Server | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software allows sending send-to-sleep notifications to the managed devices. An unauthenticated attacker in the same network of the affected system can abuse these notifications to cause a Denial-of-Service… | |
| Modificada | Media (6.5) | 0.39% | — | Siemens Sinema Remote Connect Server | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker in the same network of the affected system. | |
| Modificada | Alta (7.8) | 0.24% | — | Siemens Sinema Remote Connect | 19/8/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privileges and execute own code on the device. | |
| Modificada | Alta (8.8) | 22% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+5 | 12/8/2021 | 10/8/2026 | Remote Desktop Client Remote Code Execution Vulnerability |