Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

53 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.74%—Neutrinolabs XrdpFedoraproject Fedora27/9/202317/6/2026
xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially…
ModificadaMedia (6.5)0.85%—Neutrinolabs Xrdp30/8/202317/6/2026
xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such…
ModificadaCrítica (10)1.2%—Baicells Neutrino 430 FirmwareBaicells Nova430l FirmwareBaicells Nova430e FirmwareBaicells Nova436q Firmware11/2/202317/6/2026
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been…
ModificadaCrítica (9.1)0.94%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.76%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.1)0.87%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.1)0.77%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.1)0.77%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.89%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.89%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.84%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.89%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.80%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)3.3%💥 PoCBaicells Nova436q FirmwareBaicells Neutrino 430 Firmware30/3/202217/6/2026
Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)
ModificadaAlta (7.8)0.49%—Neutrinolabs XrdpFedoraproject Fedora7/2/202217/6/2026
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and…
ModificadaAlta (7.8)2.4%—Neutrinolabs Xrdp30/6/202017/6/2026
The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to…
ModificadaAlta (8.4)0.41%—Neutrinolabs XrdpDebian Linux23/11/201717/6/2026
The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
ModificadaAlta (7.3)1.2%—Neutrinolabs Xrdp17/3/201717/6/2026
xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not being properly initialized, with a potential consequence of incorrect configurations or elevation of privileges, aka a pam_limits.so bypass.
ModificadaCrítica (9.8)1.3%—Neutrinolabs XrdpDebian Linux16/12/201616/6/2026
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
ModificadaMedia (4.9)0.95%💥 ExploitBlackberry QNX Neutrino Rtos18/3/201417/6/2026
/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.
ModificadaAlta (7.2)2.9%💥 ExploitBlackberry QNX Neutrino Rtos18/3/201417/6/2026
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.
ModificadaMedia (5.4)6.7%—Blackberry QNX Software Development PlatformBlackberry QNX Neutrino Rtos12/7/201316/6/2026
Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868 that leverage improper handling of the /dev/photon…
ModificadaAlta (7.8)8.2%—Blackberry QNX Momentics Tool SuiteBlackberry QNX Software Development PlatformBlackberry QNX Neutrino Rtos12/7/201316/6/2026
Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool Suite through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via…
ModificadaBaja (3.3)0.30%—QNX Neutrino Rtos18/10/201116/6/2026
The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a setuid program, which allows local users to overwrite files via a symlink attack.
ModificadaAlta (10)6.3%💥 ExploitNeutrino-cms Atomic Edition11/7/200816/6/2026
Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by manipulating data/sess.php in (1) usb and (2) del_pag actions. NOTE: this can be leveraged for code execution by performing an upload that bypasses the intended access…
Orbitaley — Vulnerabilidades