Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 6.4% | — | Siemens Nucleus NETSiemens Nucleus Source Code | 22/4/2021 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions < V5.2), Nucleus Source Code… | |
| Modificada | Media (5.3) | 1.4% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Source CodeSiemens Pluscontrol 1ST GEN+1 | 9/2/2021 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions < V5.2), Nucleus ReadyStart V3… | |
| Modificada | Alta (7.1) | 0.71% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus ReadystartSiemens Nucleus Safetycert+22 | 16/1/2020 | 17/6/2026 | A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8.2 < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8.2… | |
| Modificada | Media (6.5) | 1.0% | — | Nucleuscms Nucleus CMS | 10/12/2018 | 17/6/2026 | Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Nucleuscms Nucleus CMS | 8/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item. | |
| Modificada | Media (5) | 1.4% | — | Nucleuscms Nucleus CMS | 24/9/2011 | 16/6/2026 | Nucleus 3.61 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/api_nucleus.inc.php and certain other files. | |
| Modificada | Alta (9.3) | 3.3% | — | Nucleustechnologies Kernel Recovery | 15/5/2009 | 16/6/2026 | Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Macintosh 4.04 allows user-assisted attackers to execute arbitrary code via a crafted .AMHH file. | |
| Modificada | Alta (9.3) | 2.8% | — | Nucleustechnologies Kernel Recovery | 15/5/2009 | 16/6/2026 | Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Novell 4.03 allows user-assisted attackers to execute arbitrary code via a crafted .NKNT file. | |
| Modificada | Media (5) | 1.6% | — | Nucleus Group Nucleus CMS | 17/3/2009 | 16/6/2026 | Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Nucleus CMS Nucleus | 6/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Nucleus EUC-JP 3.31 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Nucleus CMS | 30/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Nucleus CMS | 12/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter. | |
| Modificada | Media (6.8) | 1.4% | — | Nucleus CMS | 11/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Nucleus before 3.24 allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly involving (1) lib/ADMIN.php and (2) lib/SKIN.php. | |
| Modificada | Crítica (9.8) | 2.2% | — | Nucleus Group Nucleus CMS | 22/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar… | |
| Modificada | Media (5.1) | 7.1% | 💥 Exploit | Nucleus Group Nucleus CMS | 25/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[DIR_LIBS] parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Nucleus Group Nucleus CMS | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter. |