Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.60%—Rockwellautomation Factorytalk View20/7/202017/6/2026
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. Rockwell Automation recommends applying patch 1126290. Before installing this patch, the…
ModificadaAlta (8.1)53%💥 ExploitRockwellautomation Factorytalk View20/7/202017/6/2026
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk…
ModificadaMedia (4.3)53%💥 ExploitRockwellautomation Factorytalk View20/7/202017/6/2026
All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users…
ModificadaAlta (7.8)47%💥 ExploitRockwellautomation Factorytalk View20/7/202017/6/2026
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before…
ModificadaAlta (8.8)0.74%—Ufactory Xarm 5 Lite FirmwareUfactory Xarm 6 FirmwareUfactory Xarm 7 Firmware15/7/202017/6/2026
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.
ModificadaCrítica (9.8)1.3%—Ufactory Xarm 5 Lite Firmware15/7/202017/6/2026
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.
ModificadaCrítica (9.1)1.4%—Ufactory Xarm Studio15/7/202017/6/2026
No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio 1.3.0 the option is missing from the menu. Assuming manual control, even by forcefully removing the current operator…
ModificadaMedia (5.4)0.70%—Django Two-factor Authentication Project Django Two-factor Authentication10/7/202017/6/2026
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authentication code. This means…
ModificadaAlta (8.8)19%💥 ExploitFactorfx Open Computer Software Inventory Next Generation30/6/202017/6/2026
OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.
ModificadaAlta (8.8)1.1%—Rockwellautomation Factorytalk Services Platform23/6/202017/6/2026
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.
ModificadaAlta (7.5)1.8%—Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic15/6/202017/6/2026
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000…
ModificadaAlta (7.5)5.2%—Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic15/6/202017/6/2026
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000…
ModificadaCrítica (9.8)12%—Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic15/6/202017/6/2026
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000…
ModificadaAlta (8.1)2.8%—Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic15/6/202017/6/2026
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000…
ModificadaMedia (4.4)0.29%—Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+35010/6/202017/6/2026
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default…
ModificadaAlta (7.5)1.1%—Jfrog Artifactory25/3/202017/6/2026
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
ModificadaMedia (6.5)0.80%—Jfrog Artifactory25/3/202017/6/2026
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
ModificadaCrítica (9.8)5.5%—Rockwellautomation Factorytalk Services Platform23/3/202017/6/2026
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.
ModificadaAlta (7.2)1.5%—Jfrog Artifactory16/3/202017/6/2026
In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."
ModificadaAlta (8.8)1.1%—Widgetfactorylimited JCE9/3/202017/6/2026
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
ModificadaAlta (8.8)5.5%💥 PoCJfrog Artifactory23/1/202017/6/2026
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions…
ModificadaCrítica (9.1)23%💥 PoCWebfactoryltd WP Database Reset16/1/202017/6/2026
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.
ModificadaAlta (8.8)2.5%—Webfactoryltd WP Database Reset16/1/202017/6/2026
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table.
ModificadaAlta (7.6)2.0%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
ModificadaMedia (5.4)1.1%—Webfactoryltd Minimal Coming Soon & Maintenance Mode9/1/202017/6/2026
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
Orbitaley — Vulnerabilidades