Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)3.2%—Remotemouse Emote Remote Mouse7/5/202117/6/2026
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur via Packet Replay. Remote unauthenticated users can execute arbitrary code via crafted UDP packets even when passwords are set.
ModificadaMedia (5.3)1.1%—Remotemouse Emote Remote Mouse7/5/202117/6/2026
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected by any authentication logic.
ModificadaMedia (5.3)1.4%—Remotemouse Emote Remote Mouse7/5/202117/6/2026
An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the process name in a specially crafted packet. This information is sent in cleartext and is not protected by any authentication logic.
ModificadaMedia (5.3)0.64%—Remotemouse Emote Remote Mouse7/5/202117/6/2026
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the process name in a crafted packet. This information is sent in cleartext and is not protected by any authentication logic.
ModificadaAlta (7.3)1.1%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+183/5/202117/6/2026
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
ModificadaMedia (5.4)1.7%💥 ExploitRemoteclinic Remote Clinic21/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
ModificadaMedia (5.4)1.7%💥 ExploitRemoteclinic Remote Clinic21/4/202117/6/2026
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register.php
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
ModificadaMedia (5.4)1.4%—Devolutions Remote Desktop Manager1/4/202117/6/2026
An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.
ModificadaMedia (5.4)1.2%—Devolutions Remote Desktop Manager1/4/202117/6/2026
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.
ModificadaMedia (5.4)0.56%—Fujitsu Serverview Remote Management17/3/202117/6/2026
Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in the HTTP error response pages.
ModificadaAlta (8.8)0.90%—Siemens Sinema Remote Connect Server15/3/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integrity and gain information from logs and templates of the service.
ModificadaAlta (8.8)0.97%—Siemens Sinema Remote Connect Server15/3/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user…
ModificadaAlta (7.8)62%—Microsoft Remote Development11/3/202119/8/2026
Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…
ModificadaCrítica (9.8)3.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3…
ModificadaMedia (4.8)1.8%—Zohocorp Manageengine Remote Access Plus3/2/202117/6/2026
Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.
ModificadaMedia (5.5)0.19%—Canonical Remote-login-service13/1/202116/6/2026
In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue affects version 1.0.0-0ubuntu3 and prior versions.
ModificadaAlta (8.8)3.2%—Microsoft Remote DesktopMicrosoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows Server 2016+112/1/202117/6/2026
Windows Remote Desktop Security Feature Bypass Vulnerability
ModificadaMedia (5.3)1.7%—Parallels Remote Application Server25/12/202017/6/2026
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a "host" value. In other words, after an attacker's web browser sent a request to the…
ModificadaAlta (7.8)0.34%—Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+2924/11/202017/6/2026
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Orbitaley — Vulnerabilidades