Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 8.3% | — | Zohocorp Manageengine Desktop CentralZohocorp Manageengine Remote Access Plus | 2/10/2020 | 17/6/2026 | A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus before 10.1.2119.1. By exploiting this issue, an attacker-controlled server can force the client to skip TLS… | |
| Modificada | Alta (7.8) | 0.30% | — | IBM Security Verify Privilege Vault Remote On-premises | 29/9/2020 | 17/6/2026 | IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884. | |
| Modificada | Alta (7.8) | 0.82% | — | Schneider-electric Scadapack 7X Remote Connect | 16/9/2020 | 17/6/2026 | A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user. | |
| Modificada | Alta (8.8) | 1.2% | — | Schneider-electric Scadapack 7X Remote Connect | 16/9/2020 | 17/6/2026 | A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders. | |
| Modificada | Media (5.5) | 0.88% | — | Schneider-electric Scadapack 7X Remote Connect | 16/9/2020 | 17/6/2026 | A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file. | |
| Modificada | Alta (7.8) | 1.4% | — | Schneider-electric Scadapack 7X Remote Connect | 16/9/2020 | 17/6/2026 | A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer. | |
| Modificada | Media (4.3) | 0.52% | — | Jenkins Parameterized Remote Trigger | 1/9/2020 | 17/6/2026 | Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system. | |
| Modificada | Crítica (9.8) | 3.8% | — | Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control | 6/8/2020 | 17/6/2026 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet. | |
| Modificada | Crítica (9.9) | 4.0% | — | Parallels Remote Application Server | 24/7/2020 | 17/6/2026 | Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it… | |
| Modificada | Alta (7.5) | 2.0% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+12 | 22/7/2020 | 17/6/2026 | CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation. | |
| Modificada | Alta (7.8) | 0.37% | — | Vmware FusionVmware Horizon ClientVmware Remote Console | 10/7/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user… | |
| Modificada | Alta (7.8) | 0.50% | 💥 PoC | Fabulatech USB FOR Remote Desktop | 17/6/2020 | 17/6/2026 | ftusbbus2.sys in FabulaTech USB for Remote Desktop through 2020-02-19 allows privilege escalation via crafted IoCtl code related to a USB HID device. | |
| Modificada | Alta (7) | 0.22% | — | Vmware FusionVmware Horizon ClientVmware Remote Console | 29/5/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with… | |
| Modificada | Alta (7.5) | 0.92% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234). | |
| Modificada | Alta (8.8) | 2.5% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution. | |
| Modificada | Media (6.5) | 1.1% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine. | |
| Modificada | Crítica (9.8) | 1.3% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17. | |
| Modificada | Alta (7.5) | 1.2% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database. | |
| Modificada | Alta (7.5) | 1.3% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | /server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine. | |
| Modificada | Crítica (9.8) | 0.84% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak. | |
| Modificada | Alta (7.5) | 1.2% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /common/, /engine/, /flash/, /images/, /Images/, /jscripts/, /lang/, /layout/, /programs/, and /sms/. | |
| Modificada | Media (5.3) | 1.1% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames. | |
| Analizada | Media (6.5) | 86% | ⚠ Explotación activa💥 Exploit | Saltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2 | 30/4/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Saltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+1 | 30/4/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run… | |
| Modificada | Alta (7.5) | 1.9% | — | Visam Vbase EditorVisam Vbase Web-remote | 3/4/2020 | 17/6/2026 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources. |