Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.93% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+7 | 25/1/2022 | 17/6/2026 | On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (7.5) | 0.95% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+7 | 25/1/2022 | 17/6/2026 | On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which… | |
| Modificada | Media (6.5) | 1.4% | — | Coins-global Coins Construction Cloud | 24/1/2022 | 17/6/2026 | An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointing to arbitrary websites. | |
| Modificada | Media (6.1) | 1.1% | — | Coins-global Coins Construction Cloud | 24/1/2022 | 17/6/2026 | An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site scripting (XSS) via malicious links (affecting the search window and activity view window). | |
| Modificada | Media (6.1) | 1.1% | — | Coins-global Coins Construction Cloud | 24/1/2022 | 17/6/2026 | An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs. | |
| Modificada | Media (6.5) | 1.6% | — | Coins-global Coins Construction Cloud | 24/1/2022 | 17/6/2026 | An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service attacks via forced server crashes. | |
| Modificada | Alta (8.8) | 1.5% | — | Coins-global Coins Construction Cloud | 24/1/2022 | 17/6/2026 | An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel. | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Media (6.1) | 0.73% | — | Globaldatingsoftware Premiumdatingscript | 9/12/2021 | 17/6/2026 | A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description parameter in assets/sources/instagram.php script. | |
| Modificada | Media (6.5) | 0.94% | — | Globaldatingsoftware Premiumdatingscript | 9/12/2021 | 17/6/2026 | An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Globaldatingsoftware Premiumdatingscript | 9/12/2021 | 17/6/2026 | An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. . | |
| Modificada | Crítica (9.8) | 1.3% | — | Globaldatingsoftware Premiumdatingscript | 9/12/2021 | 17/6/2026 | An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php. | |
| Modificada | Alta (7.8) | 0.88% | — | Sonicwall Global VPN Client | 8/12/2021 | 17/6/2026 | SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target system. | |
| Modificada | Media (5.3) | 0.69% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker on the same network as the device to access administrative pages that could result in information disclosure or device firmware update with verified firmware. | |
| Modificada | Media (5.3) | 0.49% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | Some device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the communication channel being accessible by an attacker. | |
| Modificada | Media (6.5) | 0.42% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same subnet to download an encrypted log file containing sensitive information such as WiFi SSID and password. | |
| Modificada | Media (6.5) | 0.40% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device. | |
| Modificada | Media (4.6) | 0.09% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages. | |
| Modificada | Media (6.8) | 0.24% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device. | |
| Modificada | Alta (7.8) | 0.17% | — | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services. | |
| Modificada | Alta (8.8) | 60% | 💥 Exploit | Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+17 | 12/11/2021 | 17/6/2026 | An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device. | |
| Analizada | Alta (7.5) | 25% | 💥 PoC | Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+26 | 11/11/2021 | 23/9/2026 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network… | |
| Modificada | Media (4.6) | 0.64% | — | Oracle Secure Global Desktop | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. Successful… | |
| Modificada | Media (5.4) | 0.80% | — | Oracle Secure Global Desktop | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. Successful… | |
| Modificada | Alta (8.1) | 1.4% | — | Paloaltonetworks Globalprotect | 13/10/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.9 on… |