Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

512 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)3.2%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
ModificadaAlta (7.8)5.4%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaAlta (7.8)2.7%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaAlta (7.8)2.7%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file.
ModificadaAlta (7.8)2.5%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
ModificadaBaja (3.3)1.9%—Adobe XMP Toolkit Software Development KITDebian Linux1/9/202117/6/2026
XMP Toolkit SDK versions 2020.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of arbitrary memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a…
ModificadaAlta (7.5)1.0%—Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+33/8/202117/6/2026
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
ModificadaAlta (7.5)0.96%—Codesys Runtime Toolkit3/8/202117/6/2026
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.
ModificadaCrítica (9.8)1.1%—Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+33/8/202117/6/2026
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
ModificadaMedia (5.7)12%—Schneider-electric C-bus Toolkit21/7/202117/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.
AnalizadaAlta (7.5)7.2%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2525/5/202117/6/2026
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
AnalizadaAlta (7.5)7.4%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2525/5/202117/6/2026
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
AnalizadaMedia (5.3)0.27%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
ModificadaAlta (7.3)1.1%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+183/5/202117/6/2026
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
ModificadaAlta (7.5)1.4%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+73/5/202117/6/2026
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
ModificadaAlta (7.2)31%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project.
ModificadaAlta (8.8)41%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded.
ModificadaAlta (7.8)27%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files.
ModificadaAlta (8.8)39%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files.
ModificadaAlta (7.8)0.77%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior)
ModificadaAlta (7.5)2.1%—Gorillatoolkit WebsocketDebian Linux2/12/202017/6/2026
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.
ModificadaCrítica (9.8)1.6%—Intel Open Webrtc Toolkit13/11/202017/6/2026
Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (7.8)0.50%—Nvidia Cuda Toolkit30/10/202017/6/2026
NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure.
ModificadaMedia (5)1.5%💥 PoCToolkit Project Toolkit1/10/202017/6/2026
In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by generating a string in a specific format. Workflows that log untrusted data to stdout may invoke these commands, resulting in the path or environment variables being…
ModificadaBaja (3.3)0.50%—Canonical Ubuntu-ui-toolkit11/9/202017/6/2026
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink attack, though this is partially mitigated by symlink and hardlink…