Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 4.9% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+16 | 5/8/2021 | 17/6/2026 | curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to… | |
| Modificada | Baja (3.7) | 6.3% | 💥 PoC | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+29 | 5/8/2021 | 17/6/2026 | libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing… | |
| Modificada | Alta (7.5) | 1.0% | — | Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+3 | 3/8/2021 | 17/6/2026 | In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+3 | 3/8/2021 | 17/6/2026 | CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. | |
| Modificada | Media (6.1) | 0.67% | — | Cgm-remote-monitor Project Cgm-remote-monitor | 16/7/2021 | 17/6/2026 | Nightscout Web Monitor (aka cgm-remote-monitor) 14.2.2 allows XSS via a crafted X-Forwarded-For header. | |
| Modificada | Alta (7.8) | 0.29% | — | Idrive Remotepc | 15/7/2021 | 17/6/2026 | iDrive RemotePC before 7.6.48 on Windows allows privilege escalation. A local and low-privileged user can force RemotePC to execute an attacker-controlled executable with SYSTEM privileges. | |
| Modificada | Alta (7.5) | 1.0% | — | Idrive Remotepc | 15/7/2021 | 17/6/2026 | iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. | |
| Modificada | Crítica (9.8) | 1.2% | — | Idrive Remotepc | 15/7/2021 | 17/6/2026 | iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980. | |
| Modificada | Media (5.5) | 0.28% | — | Idrive Remotepc | 15/7/2021 | 17/6/2026 | iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-readable %PROGRAMDATA% log files. | |
| Modificada | Baja (3.3) | 0.16% | — | Idrive Remotepc | 15/7/2021 | 17/6/2026 | iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read an encrypted version of the system's Personal Key in world-readable %PROGRAMDATA% log files. The encryption is done using a hard-coded static key and is therefore reversible by an attacker. | |
| Modificada | Media (5.3) | 0.23% | — | Idrive Remotepc | 15/7/2021 | 17/6/2026 | iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. The Personal Key is transmitted over the network while only being encrypted via a substitution cipher. | |
| Modificada | Media (5.5) | 0.11% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/7/2021 | 17/6/2026 | Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could… | |
| Modificada | Media (5.5) | 0.24% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/7/2021 | 17/6/2026 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could… | |
| Modificada | Alta (7.1) | 0.22% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/7/2021 | 17/6/2026 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could… | |
| Modificada | Crítica (9.1) | 1.0% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric RemoteconnectSchneider-electric Modicon M580 Bmep581020 Firmware+28 | 14/7/2021 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70… | |
| Modificada | Alta (7.1) | 0.22% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/7/2021 | 17/6/2026 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could… | |
| Modificada | Crítica (9.1) | 4.0% | — | Solarwinds Dameware Mini Remote Control | 13/7/2021 | 17/6/2026 | In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. | |
| Modificada | Alta (7.8) | 1.0% | 💥 Exploit | Remotemouse Emote Interactive Studio | 24/6/2021 | 17/6/2026 | Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections. | |
| Modificada | Alta (7.8) | 1.5% | — | Vmware APP VolumesVmware Remote ConsoleVmware Tools | 23/6/2021 | 17/6/2026 | VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this issue by placing a… | |
| Modificada | Crítica (9.1) | 33% | — | Wibu CodemeterSiemens PSS CapeSiemens Sicam 230 FirmwareSiemens Simatic Information Server+6 | 16/6/2021 | 17/6/2026 | A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server. | |
| Modificada | Media (6.5) | 0.27% | — | Sitel-sa Remote Cap/prx Firmware | 17/5/2021 | 17/6/2026 | SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the authentication passwords by analysing the network traffic. | |
| Modificada | Alta (8.8) | 0.40% | — | Sitel-sa Remote Cap/prx Firmware | 17/5/2021 | 17/6/2026 | SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could modify these credentials, leaving the administrators of the device without access. | |
| Modificada | Alta (7.8) | 53% | — | Microsoft Remote | 11/5/2021 | 17/6/2026 | Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability | |
| Modificada | Alta (8.1) | 1.1% | — | Remotemouse Emote Remote Mouse | 7/5/2021 | 17/6/2026 | An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings. | |
| Modificada | Crítica (9.8) | 3.6% | — | Remotemouse Emote Remote Mouse | 7/5/2021 | 17/6/2026 | An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with no prior authorization or authentication. |