Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

92 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.6%—HP Device Manager12/6/202317/6/2026
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
ModificadaAlta (8.8)1.6%—HP Device Manager12/6/202317/6/2026
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
ModificadaCrítica (9.8)1.7%—HP Device Manager12/6/202317/6/2026
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
ModificadaAlta (7.8)0.67%—HP Device Manager12/6/202317/6/2026
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.
ModificadaAlta (7.5)0.53%—Honeywell Onewireless Network Wireless Device Manager Firmware30/5/202317/6/2026
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1
ModificadaMedia (6.8)0.29%—Honeywell Onewireless Network Wireless Device Manager Firmware30/5/202317/6/2026
An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in…
ModificadaMedia (6.5)0.47%—Honeywell Onewireless Network Wireless Device Manager Firmware30/5/202317/6/2026
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
ModificadaMedia (5.3)27%—Audiocodes Device Manager Express29/5/202317/6/2026
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.
ModificadaMedia (5.4)41%—Audiocodes Device Manager Express29/5/202317/6/2026
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.
ModificadaAlta (7.2)24%—Audiocodes Device Manager Express29/5/202317/6/2026
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.
ModificadaCrítica (9.8)37%—Audiocodes Device Manager Express29/5/202317/6/2026
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.
ModificadaAlta (7.2)1.2%—Audiocodes Device Manager Express29/5/202317/6/2026
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhoneFirmwareEdit.php.
ModificadaCrítica (9.8)26%—Audiocodes Device Manager Express29/5/202317/6/2026
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.
ModificadaAlta (7.8)0.54%—Zohocorp Manageengine Mobile Device Manager Plus12/11/202217/6/2026
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.
ModificadaAlta (7.2)3.4%—Cisco ISA 3000 FirmwareCisco ASA 5585-x FirmwareCisco ASA 5512-x FirmwareCisco ASA 5515-x Firmware+124/6/202217/6/2026
A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrative privileges to upload an ASDM image that contains malicious code to a device…
ModificadaMedia (5.5)0.42%—Cisco Adaptive Security Device Manager22/6/202217/6/2026
A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this issue to be exploited. This vulnerability is…
ModificadaMedia (5.3)0.40%—Axis Device Manager25/8/202117/6/2026
A user with permission to log on to the machine hosting the AXIS Device Manager client could under certain conditions extract a memory dump from the built-in Windows Task Manager application. The memory dump may potentially contain credentials of connected Axis devices.
ModificadaCrítica (9.8)4.5%—Nascent Remkon Device Manager24/8/202117/6/2026
The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution.
ModificadaAlta (7.5)1.7%—Nascent Remkon Device Manager24/8/202117/6/2026
In NASCENT RemKon Device Manager 4.0.0.0, a Directory Traversal vulnerability in a log-reading function in maintenance/readLog.php allows an attacker to read any file via a specialized URL.
ModificadaCrítica (9.8)1.9%—Nascent Remkon Device Manager24/8/202117/6/2026
A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.
ModificadaAlta (8.8)1.9%—Cisco Firepower Device Manager On-box22/7/202117/6/2026
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is due to insufficient sanitization of user input on specific REST API commands.…
ModificadaAlta (8.1)20%—Cisco Adaptive Security Device Manager8/7/202117/6/2026
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An…
ModificadaMedia (6.5)1.2%—Cisco Firepower Device Manager29/4/202117/6/2026
A vulnerability in filesystem usage management for Cisco Firepower Device Manager (FDM) Software could allow an authenticated, remote attacker to exhaust filesystem resources, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to the insufficient management of available…
ModificadaMedia (5.4)0.98%—Cisco Firepower Device Manager29/4/202117/6/2026
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected device. This vulnerability is due to the improper handling of XML External Entity (XXE) entries when parsing…
ModificadaAlta (7.8)0.42%—Siemens Simatic PCS 7Siemens Simatic Process Device ManagerSiemens Simatic Step 7Siemens Sinamics Starter10/6/202017/6/2026
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A buffer overflow…