Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 0.31% | — | Spice-space UsbredirRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 24/2/2022 | 17/6/2026 | A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination. | |
| Modificada | Alta (7.5) | 0.95% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 11/2/2022 | 17/6/2026 | A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior) | |
| Modificada | Media (6.1) | 0.60% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 9/2/2022 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser… | |
| Modificada | Alta (8.1) | 0.41% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 9/2/2022 | 17/6/2026 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a rogue website. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)… | |
| Modificada | Crítica (9.8) | 1.1% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 9/2/2022 | 17/6/2026 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and… | |
| Modificada | Media (5.3) | 0.79% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware | 9/2/2022 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and… | |
| Modificada | Alta (7.8) | 0.22% | — | Citrix Workspace | 9/2/2022 | 17/6/2026 | An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. | |
| Modificada | Media (4.3) | 0.65% | — | Bracketspace Advanced Cron Manager | 7/2/2022 | 17/6/2026 | The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example | |
| Modificada | Media (5.5) | 0.35% | — | Ivanti Workspace Control | 10/1/2022 | 17/6/2026 | A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector. | |
| Modificada | Alta (8.8) | 1.1% | — | Vmware Workspace ONE Access | 20/12/2021 | 17/6/2026 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify. | |
| Modificada | Alta (7.5) | 1.6% | — | Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access | 20/12/2021 | 17/6/2026 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Workspace ONE UEM Console | 17/12/2021 | 1/10/2026 | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to… | |
| Modificada | Alta (7.5) | 2.1% | — | Ivanti Workspace Control | 15/12/2021 | 17/6/2026 | Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity. | |
| Modificada | Alta (7.2) | 1.1% | — | Siemens Teamcenter Active Workspace | 14/12/2021 | 17/6/2026 | A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.11), Teamcenter Active Workspace V5.0 (All versions < V5.0.10), Teamcenter Active Workspace V5.1 (All versions < V5.1.6), Teamcenter Active Workspace V5.2 (All versions < V5.2.3). The application contains an unsafe unzipping… | |
| Modificada | Media (5.5) | 0.29% | — | IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Space Management | 13/12/2021 | 17/6/2026 | IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (8.8) | 0.55% | — | Amazon Workspaces | 7/12/2021 | 17/6/2026 | Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (8.8) | 0.48% | — | Amazon Workspaces | 7/12/2021 | 17/6/2026 | Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Media (5.9) | 0.42% | — | Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+2 | 23/11/2021 | 17/6/2026 | There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module… | |
| Modificada | Media (6.1) | 78% | 💥 Exploit | Montala Resourcespace | 15/11/2021 | 17/6/2026 | ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be executed within the context of the victim's… | |
| Modificada | Crítica (9.1) | 75% | — | Montala Resourcespace | 15/11/2021 | 17/6/2026 | A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become… | |
| Modificada | Crítica (9.8) | 68% | — | Montala Resourcespace | 15/11/2021 | 17/6/2026 | A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An… | |
| Modificada | Media (4.8) | 0.93% | — | Bracketspace Notification | 1/11/2021 | 17/6/2026 | The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in… | |
| Modificada | Alta (8.8) | 1.8% | — | Uyuni-project UyuniSpacewalk Project Spacewalk | 1/11/2021 | 17/6/2026 | Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to the installation setup. This can lead… | |
| Modificada | Alta (7) | 0.26% | 💥 PoC | Sophos Secure Workspace | 30/10/2021 | 17/6/2026 | A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115. |