Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)0.31%—Spice-space UsbredirRedhat Enterprise LinuxFedoraproject FedoraDebian Linux24/2/202217/6/2026
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
ModificadaAlta (7.5)0.95%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware11/2/202217/6/2026
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior)
ModificadaMedia (6.1)0.60%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware9/2/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser…
ModificadaAlta (8.1)0.41%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware9/2/202217/6/2026
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a rogue website. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)…
ModificadaCrítica (9.8)1.1%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware9/2/202217/6/2026
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and…
ModificadaMedia (5.3)0.79%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware9/2/202217/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and…
ModificadaAlta (7.8)0.22%—Citrix Workspace9/2/202217/6/2026
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
ModificadaMedia (4.3)0.65%—Bracketspace Advanced Cron Manager7/2/202217/6/2026
The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example
ModificadaMedia (5.5)0.35%—Ivanti Workspace Control10/1/202217/6/2026
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
ModificadaAlta (8.8)1.1%—Vmware Workspace ONE Access20/12/202117/6/2026
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.
ModificadaAlta (7.5)1.6%—Vmware Identity ManagerVmware Vrealize AutomationVmware Workspace ONE Access20/12/202117/6/2026
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitVmware Workspace ONE UEM Console17/12/20211/10/2026
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to…
ModificadaAlta (7.5)2.1%—Ivanti Workspace Control15/12/202117/6/2026
Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
ModificadaAlta (7.2)1.1%—Siemens Teamcenter Active Workspace14/12/202117/6/2026
A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.11), Teamcenter Active Workspace V5.0 (All versions < V5.0.10), Teamcenter Active Workspace V5.1 (All versions < V5.1.6), Teamcenter Active Workspace V5.2 (All versions < V5.2.3). The application contains an unsafe unzipping…
ModificadaMedia (5.5)0.29%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Space Management13/12/202117/6/2026
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaAlta (8.8)0.55%—Amazon Workspaces7/12/202117/6/2026
Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
ModificadaAlta (8.8)0.48%—Amazon Workspaces7/12/202117/6/2026
Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
ModificadaMedia (5.9)0.42%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+223/11/202117/6/2026
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module…
ModificadaMedia (6.1)78%💥 ExploitMontala Resourcespace15/11/202117/6/2026
ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php via the wordpress_user parameter. If an attacker is able to persuade a victim to visit a crafted URL, malicious JavaScript content may be executed within the context of the victim's…
ModificadaCrítica (9.1)75%—Montala Resourcespace15/11/202117/6/2026
A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become…
ModificadaCrítica (9.8)68%—Montala Resourcespace15/11/202117/6/2026
A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An…
ModificadaMedia (4.8)0.93%—Bracketspace Notification1/11/202117/6/2026
The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in…
ModificadaAlta (8.8)1.8%—Uyuni-project UyuniSpacewalk Project Spacewalk1/11/202117/6/2026
Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to the installation setup. This can lead…
ModificadaAlta (7)0.26%💥 PoCSophos Secure Workspace30/10/202117/6/2026
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.