Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.73% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender… | |
| Analizada | Crítica (9.8) | 0.52% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089… | |
| Analizada | Crítica (9.8) | 0.50% | — | MongodbNetapp Astra Control CenterNetapp Ontap Tools | 7/3/2024 | 17/6/2026 | Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate… | |
| Modificada | Alta (7.5) | 3.2% | 💥 PoC | Nodejs Node.jsNetapp Astra Control Center | 20/2/2024 | 17/6/2026 | A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The… | |
| Modificada | Media (5.3) | 0.54% | — | IBM Sterling Control Center | 19/1/2024 | 17/6/2026 | IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257874. | |
| Modificada | Alta (7.5) | 0.43% | — | Juniper Paragon Active Assurance Control Center | 12/1/2024 | 17/6/2026 | An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based attacker to access reports without authenticating, potentially containing sensitive configuration information. A feature was introduced in version 3.1.0 of the Paragon Active… | |
| Modificada | Alta (7.8) | 0.20% | — | Dell Rugged Control Center | 2/12/2023 | 17/6/2026 | Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading to privilege escalation on the system. | |
| Modificada | Alta (7.8) | 0.20% | — | Dell Rugged Control Center | 2/12/2023 | 17/6/2026 | Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to privilege escalation on the system. | |
| Modificada | Baja (3.3) | 0.18% | — | Dell Rugged Control Center | 1/12/2023 | 17/6/2026 | Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (4.8) | 0.45% | — | Gbcom LAC WEB Control Center | 22/6/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device. | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Kardex Control Center | 15/2/2023 | 17/6/2026 | Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of including local files, as well as remote… | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Rugged Control Center | 1/2/2023 | 17/6/2026 | Dell Rugged Control Center, versions prior to 4.5, contain an Improper Input Validation in the Service EndPoint. A Local Low Privilege attacker could potentially exploit this vulnerability, leading to an Escalation of privileges. | |
| Modificada | Alta (8.4) | 0.73% | — | Juniper Paragon Active Assurance Control Center | 18/10/2022 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, a stored XSS (or persistent), in the Control Center Controller web pages of Juniper Networks Paragon Active Assurance (Formerly Netrounds) allows a high-privilege attacker with 'WRITE' permissions to store one or… | |
| Modificada | Alta (7.8) | 0.22% | — | Intel Control Center | 18/8/2022 | 17/6/2026 | Improper buffer restrictions for some Intel(R) NUC 9 Extreme Laptop Kit drivers before version 2.2.0.22 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.65% | — | Cisco IOT Control Center | 22/7/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied… | |
| Modificada | Media (6.5) | 1.1% | — | Asus Control Center | 20/6/2022 | 17/6/2026 | ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data. | |
| Modificada | Media (6.5) | 0.89% | — | Asus Control Center | 20/6/2022 | 17/6/2026 | ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service. | |
| Modificada | Alta (7.8) | 0.67% | 💥 PoC | Intel Killer Control Center | 12/5/2022 | 17/6/2026 | Improper access control for the Intel(R) Killer(TM) Control Center software before version 2.4.3337.0 may allow an authorized user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 0.96% | — | Juniper Paragon Active Assurance Control Center | 14/4/2022 | 17/6/2026 | An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration information. A feature was introduced in version 3.1 of the Paragon Active… | |
| Modificada | Alta (8.8) | 2.9% | — | Webgate Control CenterWebgate Edvr Manager | 22/7/2021 | 17/6/2026 | Multiple stack-based buffer overflows in WebGate eDVR Manager and Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) TCPDiscover or (2) TCPDiscover2 function in the WESPDiscovery.WESPDiscoveryCtrl.1 control. | |
| Modificada | Alta (8.8) | 14% | 💥 Exploit | Webgateinc Control Center | 22/7/2021 | 17/6/2026 | Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo function in the FileConverter.FileConverterCtrl.1 control, (2) Login function in the LoginContoller.LoginControllerCtrl.1 control, or (3) GetThumbnail function in the… | |
| Modificada | Media (6.5) | 0.68% | — | Abinitio Control>center | 27/5/2021 | 17/6/2026 | Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitrary files. Fixed in v4.0.2.6 and v4.0.3.1. | |
| Modificada | Media (5.3) | 0.94% | — | IBM Control Center | 19/5/2021 | 17/6/2026 | IBM Control Center 6.2.0.0 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 198763. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Control Center | 19/5/2021 | 17/6/2026 | IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198761. |