Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.81% | — | Azeotech Daqfactory | 5/11/2021 | 17/6/2026 | Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory. | |
| Modificada | Alta (7.8) | 0.81% | — | Azeotech Daqfactory | 5/11/2021 | 17/6/2026 | The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown. | |
| Modificada | Media (6.1) | 5.8% | 💥 Exploit | Myfactory FMS | 18/10/2021 | 17/6/2026 | myfactory.FMS before 7.1-912 allows XSS via the Error parameter. | |
| Modificada | Media (6.1) | 5.8% | 💥 Exploit | Myfactory FMS | 18/10/2021 | 17/6/2026 | myfactory.FMS before 7.1-912 allows XSS via the UID parameter. | |
| Modificada | Media (5.5) | 0.22% | — | SAP Successfactors Mobile | 12/10/2021 | 17/6/2026 | A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, which allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, which can lead to denial of service. The vulnerability is related to Android… | |
| Modificada | Media (4.8) | 0.62% | — | Dfactory Post Views Counter | 20/9/2021 | 17/6/2026 | The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.62% | — | Webfactoryltd Maintenance | 23/8/2021 | 17/6/2026 | The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend | |
| Modificada | Alta (7.1) | 0.30% | — | Suse Linux Enterprise ServerOpensuse Factory | 28/7/2021 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3… | |
| Modificada | Media (5.4) | 0.63% | — | Webfactoryltd WP Reset | 12/7/2021 | 17/6/2026 | The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Alta (7.8) | 0.37% | — | Samsung Factorycamerafb | 8/7/2021 | 17/6/2026 | Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege. | |
| Modificada | Media (6.1) | 1.2% | — | Mlfactory Dsgvo ALL IN ONE FOR WP | 24/5/2021 | 17/6/2026 | The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This could allow unauthenticated attackers to… | |
| Modificada | Alta (7.8) | 0.26% | — | Opensuse Factory | 5/5/2021 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions. | |
| Modificada | Crítica (10) | 4.2% | — | Rockwellautomation Factorytalk Services Platform | 18/3/2021 | 17/6/2026 | In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly. | |
| Modificada | Alta (7.2) | 1.2% | — | Webfactoryltd 301 Redirects | 18/3/2021 | 17/6/2026 | Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections. | |
| Analizada | Crítica (9.8) | 64% | ⚠ Explotación activa💥 PoC | Rockwellautomation Factorytalk Services PlatformRockwellautomation Rslogix 5000Rockwellautomation Studio 5000 Logix Designer | 3/3/2021 | 17/6/2026 | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact… | |
| Modificada | Alta (7.5) | 34% | — | Rockwellautomation Factorytalk Diagnostics | 29/12/2020 | 17/6/2026 | An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer… | |
| Modificada | Media (5.5) | 4.8% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected. | |
| Modificada | Alta (7.5) | 39% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx… | |
| Modificada | Alta (7.5) | 25% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected. | |
| Modificada | Alta (7.5) | 3.9% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address… | |
| Modificada | Alta (7.5) | 1.9% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a denial-of-service condition on the device. | |
| Modificada | Crítica (9.8) | 6.8% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution. | |
| Modificada | Crítica (9.8) | 69% | 💥 Exploit | Jfrog Artifactory | 12/10/2020 | 17/6/2026 | Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0. | |
| Modificada | Media (5.1) | 0.22% | — | Twilio Authy 2-factor Authentication | 10/9/2020 | 17/6/2026 | A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking the application with a PIN on older Android devices (effectively bypassing the PIN requirement). | |
| Modificada | Alta (8.4) | 0.39% | — | RSA Multifactor Authentication Agent | 31/7/2020 | 17/6/2026 | Authentication Bypass Vulnerability RSA MFA Agent 2.0 for Microsoft Windows contains an Authentication Bypass vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability by using an alternate path to bypass authentication in order to gain full access to the system. |