Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

838 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.32%—Thalesgroup Safenet Authentication Service Remote Desktop Gateway19/1/202217/6/2026
A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.
ModificadaMedia (6.5)0.58%—Thalesgroup Safenet Windows Logon Agent20/12/202117/6/2026
A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine.
ModificadaMedia (4.3)0.70%—F-secure Safe16/12/202117/6/2026
An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafted a malicious URL, if user does not carefully pay attention to url, user may be tricked to think content may be coming from a valid domain, while it comes from another. This is performed by using a…
ModificadaMedia (4.3)0.75%—F-secure Safe10/12/202117/6/2026
A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker can leverage this to perform spoofing attack.
ModificadaAlta (7.8)0.25%—Intel Safestring Library17/11/202117/6/2026
Integer overflow in the Safestring library maintained by Intel(R) may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.5)25%💥 PoCBalasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+2611/11/202123/9/2026
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network…
ModificadaAlta (7.5)0.99%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via…
ModificadaAlta (7.5)1.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.
ModificadaAlta (7.5)1.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.
ModificadaCrítica (9.8)2.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code…
ModificadaCrítica (9.8)2.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
ModificadaCrítica (9.8)2.2%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
ModificadaCrítica (9.8)2.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
ModificadaCrítica (9.8)2.1%—NEC Clusterpro XNEC Clusterpro X SingleserversafeNEC Expresscluster XNEC Expresscluster X Singleserversafe3/11/202117/6/2026
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.
ModificadaAlta (7.5)0.93%—F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security ManagerF5 Big-ip Datasafe14/9/202117/6/2026
On version 16.0.x before 16.0.1.2, when a BIG-IP ASM and DataSafe profile are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (4.3)0.41%—Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+2310/9/202117/6/2026
All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet communications between affected devices.
ModificadaCrítica (9.8)1.8%—Safecurl Project Safecurl20/8/202117/6/2026
SafeCurl before 0.9.2 has a DNS rebinding vulnerability.
ModificadaCrítica (9.8)1.8%—Blackberry QNX Software Development PlatformBlackberry QNX OS FOR MedicalBlackberry QNX OS FOR Safety17/8/202117/6/2026
An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially…
ModificadaBaja (3.5)1.1%—F-secure Safe11/8/202117/6/2026
A address bar spoofing vulnerability was discovered in Safe Browser for iOS. Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. A remote attacker can leverage this to perform address bar spoofing attack.
ModificadaBaja (3.5)1.1%—F-secure Safe11/8/202117/6/2026
An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a window, covering the original content. A remote attacker can…
ModificadaMedia (4.1)0.80%—F-secure Safe5/8/202117/6/2026
Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. Exploiting the vulnerability requires the user to click on a specially crafted, seemingly legitimate URL containing an embedded malicious redirect while…
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaAlta (7.8)0.94%—Schneider-electric Sosafe Configurable21/7/202117/6/2026
A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file.
ModificadaAlta (7.8)0.33%—Ysoft Safeq14/7/202117/6/2026
Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by overwriting the executable file via an alternative data stream.
ModificadaCrítica (9.8)3.3%—Just-safe-set Project Just-safe-set7/7/202117/6/2026
Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.
Orbitaley — Vulnerabilidades