Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2747▼ 495 respecto a la semana anterior
Críticas / altas1308▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.48% | — | IBM Business Automation WorkflowIBM Business Process Manager | 17/12/2021 | 17/6/2026 | IBM Business Automation Workflow 18.0, 19.0, 20,0 and 21.0 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within… | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.1) | 0.30% | — | Wibu Codemeter RuntimeSiemens PSS CapeSiemens PSS ESiemens PSS Odms+6 | 14/11/2021 | 17/6/2026 | In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions. | |
| Modificada | Media (5.9) | 0.80% | — | IBM Business Automation WorkflowIBM Business Process Manager | 5/11/2021 | 17/6/2026 | IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. | |
| Modificada | Media (5.5) | 0.52% | — | Image-processing Project Image-processing | 2/11/2021 | 17/6/2026 | An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file. | |
| Modificada | Media (6.5) | 4.6% | — | Apache MinaOracle Banking PaymentsOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+5 | 1/11/2021 | 17/6/2026 | In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater. | |
| Modificada | Alta (8.1) | 0.80% | — | Siemens Simatic Process Historian 2013Siemens Simatic Process Historian 2014Siemens Simatic Process Historian 2019Siemens Simatic Process Historian 2020 | 12/10/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All versions), SIMATIC Process Historian 2020 (All versions). An interface in the software that is used for critical… | |
| Modificada | Media (5.4) | 0.50% | — | IBM Business Automation WorkflowIBM Business Process Manager | 29/9/2021 | 17/6/2026 | IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0.2 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the… | |
| Modificada | Alta (8.8) | 1.4% | — | Eigentech Natural Language Processing | 7/9/2021 | 17/6/2026 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to create a super user account with a defined password. This directly leads to privilege escalation. | |
| Modificada | Alta (8.8) | 1.3% | — | Eigentech Natural Language Processing | 7/9/2021 | 17/6/2026 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more. | |
| Modificada | Alta (8.1) | 0.95% | — | Eigentech Natural Language Processing | 7/9/2021 | 17/6/2026 | In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-in user (guest, standard, or admin) to view and modify information. | |
| Modificada | Alta (7.5) | 0.94% | — | Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+45 | 2/9/2021 | 17/6/2026 | A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers… | |
| Modificada | Media (6.5) | 0.84% | — | Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+45 | 2/9/2021 | 17/6/2026 | A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all… | |
| Modificada | Media (6.5) | 0.84% | — | Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+45 | 2/9/2021 | 17/6/2026 | A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all… | |
| Modificada | Media (6.5) | 0.84% | — | Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+45 | 2/9/2021 | 17/6/2026 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all… | |
| Modificada | Alta (7.5) | 2.6% | — | Opcfoundation Local Discover ServerSiemens Simatic Process Historian OPC UA Server FirmwareSiemens Simatic NET PCSiemens Simatic Wincc+3 | 27/8/2021 | 17/6/2026 | In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer. | |
| Modificada | Alta (7.5) | 6.7% | — | JsoupQuarkusOracle Banking Trade FinanceOracle Banking Treasury Management+12 | 18/8/2021 | 17/6/2026 | jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete… | |
| Modificada | Alta (7.5) | 0.96% | — | Deferred Image Processing Project Deferred Image Processing | 13/8/2021 | 17/6/2026 | The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption. | |
| Modificada | Media (5.3) | 0.85% | — | Redhat Wildfly ElytronRedhat Build OF QuarkusRedhat Codeready StudioRedhat Data Grid+9 | 5/8/2021 | 17/6/2026 | A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Media (5.5) | 0.11% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/7/2021 | 17/6/2026 | Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could… | |
| Modificada | Media (5.5) | 0.24% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/7/2021 | 17/6/2026 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could… | |
| Modificada | Alta (7.1) | 0.22% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/7/2021 | 17/6/2026 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could… | |
| Modificada | Crítica (9.1) | 1.0% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric RemoteconnectSchneider-electric Modicon M580 Bmep581020 Firmware+28 | 14/7/2021 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70… |