Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)8.3%—Zohocorp Manageengine Desktop CentralZohocorp Manageengine Remote Access Plus2/10/202017/6/2026
A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus before 10.1.2119.1. By exploiting this issue, an attacker-controlled server can force the client to skip TLS…
ModificadaAlta (7.8)0.30%—IBM Security Verify Privilege Vault Remote On-premises29/9/202017/6/2026
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.
ModificadaAlta (7.8)0.82%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.
ModificadaAlta (8.8)1.2%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.
ModificadaMedia (5.5)0.88%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.
ModificadaAlta (7.8)1.4%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.
ModificadaMedia (4.3)0.52%—Jenkins Parameterized Remote Trigger1/9/202017/6/2026
Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
ModificadaCrítica (9.8)3.8%—Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control6/8/202017/6/2026
Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.
ModificadaCrítica (9.9)4.0%—Parallels Remote Application Server24/7/202017/6/2026
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it…
ModificadaAlta (7.5)2.0%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+1222/7/202017/6/2026
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
ModificadaAlta (7.8)0.37%—Vmware FusionVmware Horizon ClientVmware Remote Console10/7/202017/6/2026
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user…
ModificadaAlta (7.8)0.50%💥 PoCFabulatech USB FOR Remote Desktop17/6/202017/6/2026
ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code related to a USB HID device.
ModificadaAlta (7)0.22%—Vmware FusionVmware Horizon ClientVmware Remote Console29/5/202017/6/2026
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with…
ModificadaAlta (7.5)0.92%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
ModificadaAlta (8.8)2.5%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
ModificadaMedia (6.5)1.1%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.
ModificadaCrítica (9.8)1.3%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.
ModificadaAlta (7.5)1.2%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.
ModificadaAlta (7.5)1.3%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine.
ModificadaCrítica (9.8)0.84%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.
ModificadaAlta (7.5)1.2%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /common/, /engine/, /flash/, /images/, /Images/, /jscripts/, /lang/, /layout/, /programs/, and /sms/.
ModificadaMedia (5.3)1.1%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.
AnalizadaMedia (6.5)86%⚠ Explotación activa💥 ExploitSaltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+230/4/202017/6/2026
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitSaltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+130/4/202017/6/2026
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run…
ModificadaAlta (7.5)1.9%—Visam Vbase EditorVisam Vbase Web-remote3/4/202017/6/2026
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
Orbitaley — Vulnerabilidades