Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.0%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device.
ModificadaAlta (7.2)1.0%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code.
ModificadaAlta (7.8)0.21%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.
ModificadaAlta (7.8)0.26%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server.
ModificadaAlta (7.2)2.7%—Cisco DNA Spaces\22/5/202117/6/2026
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these…
ModificadaAlta (7.2)2.7%—Cisco DNA Spaces\22/5/202117/6/2026
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these…
ModificadaMedia (6.7)0.33%—Cisco DNA Spaces\22/5/202117/6/2026
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions during the execution of affected CLI commands. An attacker…
ModificadaMedia (6.7)0.33%—Cisco DNA Spaces\22/5/202117/6/2026
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. These vulnerabilities are due to insufficient restrictions during the execution of affected CLI commands. An attacker…
ModificadaAlta (8.8)0.96%—Blackberry Workspaces Server13/5/202117/6/2026
An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) version(s) 10.1, 9.1 and earlier could allow an attacker to potentially gain access to the application in the context of the targeted user’s account.
ModificadaMedia (6.1)0.80%—Vmware Workspace ONE Unified Endpoint Management11/5/202117/6/2026
VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 2003 prior to 20.3.0.23, 2001 prior to 20.1.0.32, 1912 prior…
ModificadaAlta (7.8)0.34%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space Management26/4/202117/6/2026
IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processing the current locale settings. A local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges or cause the application to…
ModificadaMedia (5.5)0.27%—IBM Spectrum Protect ClientIBM Spectrum Protect FOR Space Management26/4/202117/6/2026
IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and cause the application to crash. IBM X-Force ID: 198934
ModificadaAlta (7.5)1.4%—Appspace14/4/20219/7/2026
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.
ModificadaMedia (5.4)0.50%—Appspace14/4/202117/6/2026
Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.
ModificadaMedia (6.5)0.83%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+88/4/202117/6/2026
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions…
ModificadaAlta (8.8)0.22%—Tibco Activespaces23/3/202117/6/2026
The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows…
ModificadaMedia (5.3)0.71%—Huawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Nip6800 FirmwareHuawei S12700 Firmware+1022/3/202117/6/2026
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of…
ModificadaAlta (7.5)0.73%—Huawei IPS Module FirmwareHuawei Ngfw Module FirmwareHuawei Nip6600 FirmwareHuawei Nip6800 Firmware+322/3/202117/6/2026
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Module, NGFW Module,…
ModificadaMedia (4.4)0.19%—Huawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Secospace Usg6300 FirmwareHuawei Secospace Usg6500 Firmware+222/3/202117/6/2026
There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected product versions include: NIP6300 versions…
ModificadaAlta (7.5)0.73%—Huawei Ngfw Module FirmwareHuawei Nip6300 FirmwareHuawei Nip6600 FirmwareHuawei Nip6800 Firmware+422/3/202117/6/2026
There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft many specific packets. Successful exploit may cause some services to be abnormal. Affected products include some versions of NGFW Module, NIP6300, NIP6600,…
ModificadaAlta (7.8)0.32%—Drweb Security Space8/3/202117/6/2026
Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.
ModificadaCrítica (9.8)61%💥 ExploitAppspace25/2/202117/6/2026
Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
ModificadaMedia (5.4)0.54%—Appspace22/2/202117/6/2026
A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. Whenever another member visits that group, this payload executes.
ModificadaCrítica (9.8)1.3%—Freediskspace Project Freediskproject2/2/202117/6/2026
This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.js.
ModificadaMedia (6.8)1.2%—Juniper Junos Space15/1/202117/6/2026
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to obtain a copy of credentials managed by…
Orbitaley — Vulnerabilidades