Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)298▼ 212 respecto a la semana anterior
–

67 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)13%💥 ExploitNetgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this…
AnalizadaAlta (8.8)2.1%—Netgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System BkreProcessThread Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this…
AnalizadaCrítica (9.8)82%💥 ExploitNetgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System. Authentication is not required to exploit this vulnerability. The specific flaw…
AnalizadaAlta (8.8)66%—Netgear Prosafe Network Management System3/5/202417/6/2026
NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this…
ModificadaAlta (7.8)0.54%—Netgear Prosafe Network Management System29/11/202317/6/2026
A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.
ModificadaCrítica (9.8)1.2%—Netgear Prosafe Network Management System29/11/202317/6/2026
NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
ModificadaAlta (8.8)0.54%—Siemens Sinec Network Management SystemSiemens Sinema Server8/3/202217/6/2026
A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. This could allow an…
ModificadaAlta (7.2)1.4%—Siemens Sinec Network Management System8/3/202217/6/2026
A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected system allows to upload JSON objects that are deserialized to Java objects. Due to insecure deserialization of user-supplied content by the affected…
ModificadaAlta (7.2)3.5%—Siemens Sinec Network Management System8/3/202217/6/2026
A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). A privileged authenticated attacker could execute arbitrary commands in the local database by sending specially crafted requests to the webserver of the affected application.
ModificadaAlta (8.8)0.43%—Siemens Sinec Network Management System14/9/202117/6/2026
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). The web interface of affected devices is vulnerable to a Cross-Site Request Forgery (CSRF) attack. This could allow an attacker to manipulate the SINEC NMS configuration by tricking an unsuspecting user with administrative privileges to click…
ModificadaAlta (7.7)37%—Siemens Sinec Network Management System14/9/202117/6/2026
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). An attacker with access to the webserver of an affected system could download arbitrary files from the underlying filesystem by sending a specially crafted HTTP request.
ModificadaAlta (7.2)2.7%—Siemens Sinec Network Management System10/8/202117/6/2026
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges could exploit this vulnerability to execute…
ModificadaAlta (7.1)72%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the…
ModificadaAlta (8.3)73%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific…
ModificadaCrítica (9.8)8.2%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class. The issue results from the lack of proper…
ModificadaAlta (8.8)65%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the…
ModificadaAlta (7.1)74%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the…
ModificadaAlta (8.1)21%—Siemens Sinec Network Management SystemSiemens Sinema Server9/2/202117/6/2026
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended…
ModificadaMedia (6.7)0.46%—Siemens Simatic Automatic ToolSiemens Simatic NET PCSiemens Simatic PCS 7Siemens Simatic PCS NEO+1310/6/202017/6/2026
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All…
ModificadaMedia (5.3)1.3%—Veraxsystems Network Management System30/1/202016/6/2026
Verax NMS prior to 2.1.0 leaks connection details when any user executes a Repair Table action
ModificadaAlta (7.5)1.3%—Veraxsystems Network Management System30/1/202016/6/2026
Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive.
ModificadaMedia (5.9)2.0%—Veraxsystems Network Management System30/1/202016/6/2026
Verax NMS prior to 2.10 allows authentication via the encrypted password without knowing the cleartext password.
ModificadaCrítica (9.1)1.5%—Veraxsystems Network Management System30/1/202016/6/2026
Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities
ModificadaAlta (7.5)2.9%—Oracle Banking PlatformOracle Business Process Management SuiteOracle Communications Converged Application ServerOracle Communications Webrtc Session Controller+517/10/201817/6/2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.…
Orbitaley — Vulnerabilidades