Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 3.2% | — | Remotemouse Emote Remote Mouse | 7/5/2021 | 17/6/2026 | An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur via Packet Replay. Remote unauthenticated users can execute arbitrary code via crafted UDP packets even when passwords are set. | |
| Modificada | Media (5.3) | 1.1% | — | Remotemouse Emote Remote Mouse | 7/5/2021 | 17/6/2026 | An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected by any authentication logic. | |
| Modificada | Media (5.3) | 1.4% | — | Remotemouse Emote Remote Mouse | 7/5/2021 | 17/6/2026 | An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the process name in a specially crafted packet. This information is sent in cleartext and is not protected by any authentication logic. | |
| Modificada | Media (5.3) | 0.64% | — | Remotemouse Emote Remote Mouse | 7/5/2021 | 17/6/2026 | An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the process name in a crafted packet. This information is sent in cleartext and is not protected by any authentication logic. | |
| Modificada | Alta (7.3) | 1.1% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+18 | 3/5/2021 | 17/6/2026 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages. | |
| Modificada | Media (5.4) | 1.7% | 💥 Exploit | Remoteclinic Remote Clinic | 21/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php | |
| Modificada | Media (5.4) | 1.7% | 💥 Exploit | Remoteclinic Remote Clinic | 21/4/2021 | 17/6/2026 | Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field. | |
| Modificada | Media (5.4) | 1.8% | 💥 Exploit | Remoteclinic Remote Clinic | 13/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php. | |
| Modificada | Media (5.4) | 1.8% | 💥 Exploit | Remoteclinic Remote Clinic | 13/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register.php | |
| Modificada | Media (5.4) | 1.8% | 💥 Exploit | Remoteclinic Remote Clinic | 13/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php. | |
| Modificada | Media (5.4) | 1.8% | 💥 Exploit | Remoteclinic Remote Clinic | 13/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php. | |
| Modificada | Media (5.4) | 1.8% | 💥 Exploit | Remoteclinic Remote Clinic | 13/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php. | |
| Modificada | Media (5.4) | 1.4% | — | Devolutions Remote Desktop Manager | 1/4/2021 | 17/6/2026 | An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews. | |
| Modificada | Media (5.4) | 1.2% | — | Devolutions Remote Desktop Manager | 1/4/2021 | 17/6/2026 | Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields. | |
| Modificada | Media (5.4) | 0.56% | — | Fujitsu Serverview Remote Management | 17/3/2021 | 17/6/2026 | Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in the HTTP error response pages. | |
| Modificada | Alta (8.8) | 0.90% | — | Siemens Sinema Remote Connect Server | 15/3/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integrity and gain information from logs and templates of the service. | |
| Modificada | Alta (8.8) | 0.97% | — | Siemens Sinema Remote Connect Server | 15/3/2021 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user… | |
| Modificada | Alta (7.8) | 62% | — | Microsoft Remote Development | 11/3/2021 | 19/8/2026 | Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 6.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all… | |
| Modificada | Crítica (9.8) | 3.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3… | |
| Modificada | Media (4.8) | 1.8% | — | Zohocorp Manageengine Remote Access Plus | 3/2/2021 | 17/6/2026 | Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen. | |
| Modificada | Media (5.5) | 0.19% | — | Canonical Remote-login-service | 13/1/2021 | 16/6/2026 | In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue affects version 1.0.0-0ubuntu3 and prior versions. | |
| Modificada | Alta (8.8) | 3.2% | — | Microsoft Remote DesktopMicrosoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows Server 2016+1 | 12/1/2021 | 17/6/2026 | Windows Remote Desktop Security Feature Bypass Vulnerability | |
| Modificada | Media (5.3) | 1.7% | — | Parallels Remote Application Server | 25/12/2020 | 17/6/2026 | Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a "host" value. In other words, after an attacker's web browser sent a request to the… | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. |