Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.3% | — | Rockwellautomation Flex I/O 1794-aent/b Firmware | 14/10/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this… | |
| Modificada | Alta (7.5) | 4.2% | — | Rockwellautomation Allen-bradley Flex IO 1794-aent/b Firmware | 14/10/2020 | 17/6/2026 | An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this… | |
| Modificada | Alta (7.5) | 8.0% | — | Apache ANTGradleFedoraproject FedoraOracle Agile Engineering Data Management+33 | 1/10/2020 | 17/6/2026 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still… | |
| Modificada | Media (6.5) | 11% | 💥 PoC | Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRMOracle Communications Design Studio+34 | 19/9/2020 | 17/6/2026 | In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. | |
| Modificada | Baja (2.3) | 0.34% | — | Hms-networks Ewon Flexy FirmwareHms-networks Ewon Cosy Firmware | 18/9/2020 | 17/6/2026 | All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve… | |
| Modificada | Alta (7.5) | 0.92% | — | Flexsolution Reset Password | 17/9/2020 | 17/6/2026 | The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field. | |
| Modificada | Media (5.9) | 4.5% | — | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Flexcube Private BankingDebian Linux | 10/9/2020 | 17/6/2026 | Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original,… | |
| Modificada | Crítica (9.8) | 49% | 💥 PoC | Apache ActivemqOracle Communications Diameter Signaling RouterOracle Communications Element ManagerOracle Communications Session Report Manager+3 | 10/9/2020 | 17/6/2026 | A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack:… | |
| Modificada | Media (4.4) | 0.21% | — | Cisco Hyperflex Hx-series Software | 26/8/2020 | 17/6/2026 | A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists because sensitive information is stored as clear text. An attacker could exploit… | |
| Modificada | Crítica (9.8) | 4.4% | — | Vmware Spring IntegrationOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Supply Chain Finance+4 | 31/7/2020 | 17/6/2026 | Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains malicious code for execution… | |
| Modificada | Alta (7.5) | 1.1% | — | Flexera Flexnet Publisher | 31/7/2020 | 17/6/2026 | An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to system files or other important files on the system. | |
| Modificada | Alta (8.1) | 1.4% | — | Oracle Flexcube Investor Servicing | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Alta (7.5) | 1.3% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier,… | |
| Modificada | Alta (7.5) | 1.4% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver.… | |
| Modificada | Alta (7.5) | 0.48% | — | Baxter Prismaflex FirmwareBaxter Prismax Firmware | 29/6/2020 | 17/6/2026 | Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An attacker could observe sensitive data… | |
| Modificada | Alta (7.5) | 0.50% | — | Baxter Prismaflex FirmwareBaxter Prismax Firmware | 29/6/2020 | 17/6/2026 | Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An attacker could observe sensitive data… | |
| Modificada | Media (4.9) | 0.25% | — | Baxter Prismaflex FirmwareBaxter Prismax Firmware | 29/6/2020 | 17/6/2026 | Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service password that provides access to biomedical information, device settings, calibration settings, and network configuration. This could allow an attacker to modify device settings and calibration. | |
| Modificada | Alta (7.5) | 1.2% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard. | |
| Modificada | Crítica (9.8) | 0.97% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were granted via file creation, access race… | |
| Modificada | Media (4.6) | 0.97% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image. | |
| Modificada | Media (6.4) | 0.38% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components dependent on the laser scanner are not… | |
| Modificada | Crítica (9.8) | 0.96% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to… | |
| Modificada | Alta (7.1) | 0.90% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in combination with CVE-2020-10273 allows any attacker connected to the robot networks (wired or… | |
| Modificada | Alta (7.5) | 0.86% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed… |