Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.84%—Netop Remote Control9/1/201717/6/2026
Stack-based buffer overflow vulnerability in Netop Remote Control versions 11.53, 12.21 and prior. The affected module in the Guest client is the "Import to Phonebook" option. When a specially designed malicious file containing special characters is loaded, the overflow occurs. 12.51 is the fixed version. The Support…
ModificadaAlta (8.8)0.63%—IBM Bigfix Remote Control30/11/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
ModificadaBaja (3.7)1.6%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.
ModificadaBaja (3.7)0.66%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
ModificadaMedia (6.5)1.1%—IBM Bigfix Remote Control30/11/201617/6/2026
SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaBaja (3.3)0.31%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.
ModificadaAlta (7.8)0.28%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
ModificadaCrítica (9.8)1.5%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
ModificadaBaja (1.9)0.27%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.
ModificadaMedia (5.3)1.3%—IBM Bigfix Remote Control30/11/201617/6/2026
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.
ModificadaMedia (6.5)1.3%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerability."
ModificadaAlta (7.3)1.0%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.
ModificadaMedia (5.3)1.6%—IBM Bigfix Remote Control30/11/201617/6/2026
The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.
ModificadaMedia (6.1)1.1%—IBM Bigfix Remote Control30/11/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)2.8%—IBM Bigfix Remote Control30/11/201617/6/2026
Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.
ModificadaMedia (5.3)1.4%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.
ModificadaMedia (5.3)1.5%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
ModificadaAlta (8.1)1.3%—IBM Bigfix Remote Control25/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a brute-force approach.
ModificadaMedia (4.3)1.0%—IBM Bigfix Remote Control25/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.
ModificadaMedia (5.9)0.81%—IBM Bigfix Remote Control25/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
ModificadaCrítica (9.8)51%—Dameware Mini Remote Control17/3/201617/6/2026
Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.
ModificadaAlta (7.5)4.8%—Solarwinds Dameware Mini Remote Control17/11/201517/6/2026
Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.
ModificadaMedia (6.5)0.96%—IBM Tivoli Remote Control29/7/201316/6/2026
SQL injection vulnerability in the server component in IBM Tivoli Remote Control 5.1.2 before 5.1.2-TIV-TRC512-IF0015 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (9.3)6.9%—IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+1211/1/201316/6/2026
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control…
ModificadaAlta (9.3)6.9%—IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+1211/1/201316/6/2026
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli…