Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.8%💥 PoCJetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+910/6/202417/6/2026
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell…
AplazadaMedia (5.5)0.19%—Aquasec TrivyAI20/5/202417/6/2026
Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or…
ModificadaMedia (5.3)1.1%—Aquaforest Tiff Server30/11/202317/6/2026
The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or…
ModificadaAlta (8.8)0.76%—Aquaesolutions Aqua Drive4/10/202317/6/2026
Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and configuration files of the cloud disk…
ModificadaAlta (8.8)0.21%—Xylem Aquaview7/2/202217/6/2026
A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.
ModificadaMedia (5.4)0.50%—Javaquarkbbs Project Javaquarkbbs19/1/202217/6/2026
There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the next victim will be attacked when he accesses the tag module.
ModificadaAlta (8.8)1.5%—Terarecon Aquariusnet1/9/202117/6/2026
NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user account. To exploit this, a low-privileged user must change the service configuration or overwrite the binary service.
ModificadaAlta (8.6)1.1%—Cdnetworks Aquanplayer22/4/202117/6/2026
There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulnerability can cause information leakage.
ModificadaAlta (7.5)1.8%—Aquaforest Tiff Server18/3/202017/6/2026
Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.
ModificadaAlta (7.5)1.4%—Aquaforest Tiff Server18/3/202017/6/2026
Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.
ModificadaMedia (5.3)1.6%—Aquaforest Tiff Server18/3/202017/6/2026
Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.
ModificadaCrítica (9.8)6.7%—Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+175/2/202017/6/2026
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and…
ModificadaCrítica (9.8)4.2%—Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+175/2/202017/6/2026
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and…
ModificadaCrítica (9.8)4.2%—Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+175/2/202017/6/2026
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and…
ModificadaAlta (7.8)1.3%—Yokogawa ExaopcYokogawa ExaplogYokogawa ExaquantumYokogawa Exaquantum/batch+426/12/201917/6/2026
An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (all revisions), Exarqe (all revisions), GA10 (R1.01.01 ? R3.05.01), and…
ModificadaMedia (5.3)0.43%—Aquamaniac GwenhywfarDebian LinuxOpensuse Leap3/12/201917/6/2026
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
ModificadaAlta (7.5)0.89%—Jenkins Aqua Security Scanner25/9/201917/6/2026
Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
ModificadaMedia (5.3)0.77%—Jenkins Aqua Microscanner25/9/201917/6/2026
Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
ModificadaBaja (3.1)0.59%—Jenkins Aqua Security Severless Scanner12/9/201917/6/2026
Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.
ModificadaCrítica (9.8)1.6%—Aquaverde Aquarius CMS15/7/201917/6/2026
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The component is: log file. The attack vector is: open the file.
ModificadaAlta (8.8)1.8%—Jenkins Aqua Microscanner30/4/201917/6/2026
Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
ModificadaAlta (7.5)1.6%—Aquaverde Aquarius CMS24/4/201917/6/2026
Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances.
ModificadaAlta (7.5)1.4%—Aquaverde Aquarius CMS24/4/201917/6/2026
aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.
ModificadaAlta (8.8)1.3%—Jenkins Aqua Security Scanner4/4/201917/6/2026
Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (5.4)0.27%—Socialknowledge Aquarium Advice20/9/201417/6/2026
The Aquarium Advice (aka com.socialknowledge.aquariumadvice) application 3.7.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades