Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.31% | — | Enituretechnology Standard BOX SizesAI | 21/1/2025 | 17/6/2026 | Missing Authorization vulnerability in enituretechnology Standard Box Sizes – for WooCommerce standard-box-sizes.This issue affects Standard Box Sizes – for WooCommerce: from n/a through <= 1.6.13. | |
| Aplazada | Alta (7.5) | 0.55% | — | Connectivity Standards Alliance MatterAI | 18/12/2024 | 17/6/2026 | In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion). | |
| Aplazada | Media (5.1) | 0.61% | — | Deno Standard LibraryAI | 22/11/2024 | 17/6/2026 | The Deno Standard Library provides APIs for Deno and the Web. Prior to version 1.0.11, `http/file-server`'s `serveDir` with `showDirListing: true` option is vulnerable to cross-site scripting when the attacker is a user who can control file names in the source directory on systems with POSIX file names. Exploitation… | |
| Aplazada | Media (5.4) | 0.15% | — | Intel Advanced Link Analyzer Standard EditionAI | 13/11/2024 | 17/6/2026 | Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.3) | 0.50% | — | Opcfoundation UA .net StandardAI | 22/10/2024 | 17/6/2026 | An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credentials and cause the server performance to degrade gradually. | |
| Aplazada | Alta (7.3) | 0.51% | — | Thegreenbowvpn Windows Standard VPN ClientAIThegreenbowvpn Windows Enterprise VPN ClientAIThegreenbowvpn Android VPN ClientAIThegreenbowvpn VPN Client LinuxAI+1 | 25/9/2024 | 17/6/2026 | An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and older) allows a remote attacker to execute… | |
| Analizada | Alta (7.7) | 1.3% | — | Rockwellautomation 2800c Optixpanel Compact FirmwareRockwellautomation 2800s Optixpanel Standard FirmwareRockwellautomation Embedded Edge Compute Module Firmware | 12/9/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges. | |
| Aplazada | Media (6.9) | 0.50% | — | Intel Active Management TechnologyAIIntel Standard ManageabilityAI | 14/8/2024 | 17/6/2026 | Improper buffer restrictions in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable denial of service via network access. | |
| Aplazada | Alta (7.5) | 0.56% | — | Opcfoundation.netstandard.opc.ua.coreAI | 5/7/2024 | 17/6/2026 | A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS)… | |
| Analizada | Alta (7.5) | 1.0% | — | Opcfoundation Ua-.netstandard | 7/5/2024 | 17/6/2026 | OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Alta (7.5) | 0.50% | — | Unitronics Vision StandardAI | 19/4/2024 | 17/6/2026 | Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication. | |
| Aplazada | Alta (7.8) | 0.24% | — | Faronics Deep Freeze Server StandardAI | 12/3/2024 | 17/6/2026 | A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.4627 and earlier. This vulnerability affects the DFServ.exe file. An attacker with local user privileges could exploit this vulnerability to replace the legitimate DFServ.exe service executable with a… | |
| Modificada | Media (5.3) | 0.79% | — | Opcfoundation Ua-.netstandard | 12/12/2023 | 17/6/2026 | The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely. | |
| Modificada | Media (5.3) | 0.20% | — | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 20/11/2023 | 17/6/2026 | Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. | |
| Modificada | Baja (2.7) | 0.47% | — | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 17/10/2023 | 17/6/2026 | On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected. | |
| Modificada | Media (6.5) | 0.30% | — | Janusintl Noke Standard Smart Padlock FirmwareJanusintl Noke HD Smart Padlock FirmwareJanusintl Noke HD+ Smart Padlock Firmware | 9/10/2023 | 17/6/2026 | Nokelock Smart padlock O1 Version 5.3.0 is vulnerable to Insecure Permissions. By sending a request, you can add any device and set the device password in the Nokelock app. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 15/5/2023 | 17/6/2026 | In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise. | |
| Modificada | Alta (7.5) | 1.6% | — | Facebook Zstandard | 31/3/2023 | 17/6/2026 | A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun. | |
| Modificada | Crítica (9.8) | 1.1% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. | |
| Modificada | Media (5.3) | 0.25% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the… | |
| Modificada | Crítica (9.8) | 0.74% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device. | |
| Modificada | Media (6.1) | 0.38% | — | Wago 751-9301 FirmwareWago 752-8303/8000-002 FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 27/2/2023 | 17/6/2026 | The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability. | |
| Modificada | Media (5.9) | 0.63% | — | Wago Pfc100 FirmwareWago Pfc200 FirmwareWago Touch Panel 600 Advanced FirmwareWago Touch Panel 600 Standard Firmware+3 | 19/1/2023 | 17/6/2026 | The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull. | |
| Modificada | Alta (7.5) | 1.3% | — | Opcfoundation UA .net Standard Stack | 23/8/2022 | 17/6/2026 | OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information. | |
| Modificada | Media (5.5) | 0.19% | — | Intel Standard ManageabilityIntel Active Management Technology Firmware | 18/8/2022 | 17/6/2026 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access. |