Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.00% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not… | |
| Modificada | Alta (7.5) | 1.5% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22. | |
| Modificada | Alta (7.2) | 12% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22. | |
| Modificada | Alta (7.5) | 0.98% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability. | |
| Modificada | Alta (7.2) | 13% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path… | |
| Modificada | Alta (7.5) | 1.5% | — | Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+2 | 17/8/2022 | 17/6/2026 | A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22. | |
| Modificada | Alta (7.5) | 0.92% | — | Seagate Cortx-s3 Server | 7/4/2022 | 17/6/2026 | A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock. | |
| Modificada | Alta (7.5) | 1.3% | — | Softing Datafeed OPC SuiteSofting EdgeconnectorSofting OPCSofting Secure Integration Server+3 | 10/11/2021 | 17/6/2026 | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted. | |
| Modificada | Crítica (9.8) | 2.3% | — | Genuagate | 3/3/2021 | 17/6/2026 | An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces (Admin, Userweb, Sidechannel) can use different methods to perform the authentication of a user. A specific authentication method during login does not check the provided data… | |
| Modificada | Alta (8.8) | 3.3% | — | Softing Uagate SI FirmwareSofting Uagate MB FirmwareSofting Uagate 840d Firmware | 10/10/2019 | 17/6/2026 | An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Softing Uagate SI Firmware | 10/10/2019 | 17/6/2026 | An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable. | |
| Modificada | Alta (8.8) | 3.5% | — | Softing Uagate SI Firmware | 10/10/2019 | 17/6/2026 | An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter. | |
| Modificada | Crítica (9.8) | 2.0% | — | Softing Uagate SI Firmware | 10/10/2019 | 17/6/2026 | An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations. | |
| Modificada | Alta (7.8) | 0.41% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware | 7/6/2019 | 17/6/2026 | An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all… | |
| Modificada | Crítica (9.8) | 2.0% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware | 7/6/2019 | 17/6/2026 | An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's… | |
| Modificada | Alta (8.8) | 1.8% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware | 7/6/2019 | 17/6/2026 | An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore, the user account that controls the web application service is… | |
| Modificada | Media (6.1) | 0.82% | — | Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware | 7/6/2019 | 17/6/2026 | A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated threat actor to inject malicious code directly into the application. This affects, for example, the Profile Description field in JSON data to… | |
| Modificada | Media (6.1) | 0.83% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL. | |
| Modificada | Media (5.4) | 0.64% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names. | |
| Modificada | Media (6.1) | 0.80% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting. | |
| Modificada | Alta (7.5) | 1.4% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost. | |
| Modificada | Media (6.1) | 3.1% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter. | |
| Modificada | Media (5.4) | 0.64% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names. | |
| Modificada | Alta (7.5) | 1.7% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path. | |
| Modificada | Media (6.1) | 0.69% | — | Seagate NAS OS | 13/5/2019 | 17/6/2026 | Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names. |