Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)1.1%—Kieback Peter Neutrino GLTAIKieback Peter Sm70 PhwebAI7/1/202630/9/2026
Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to shell command injection via login form. The injected commands would execute with low privileges. The vulnerability has been fixed in version 9.40.02
ModificadaCrítica (9.8)0.61%—Neutrinolabs Xrdp12/7/202417/6/2026
xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not…
ModificadaMedia (6.5)0.74%—Neutrinolabs XrdpFedoraproject Fedora27/9/202317/6/2026
xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The vulnerability allows an out-of-bounds read within a potentially…
ModificadaMedia (6.5)0.85%—Neutrinolabs Xrdp30/8/202317/6/2026
xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such…
ModificadaAlta (8.8)3.1%💥 ExploitNotrinoserp23/3/202317/6/2026
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php.
ModificadaCrítica (10)1.2%—Baicells Neutrino 430 FirmwareBaicells Nova430l FirmwareBaicells Nova430e FirmwareBaicells Nova436q Firmware11/2/202317/6/2026
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been…
ModificadaCrítica (9.1)0.94%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.76%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.1)0.87%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.1)0.77%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_sec_process_mcs_data_CS_CORE() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.1)0.77%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_caps_process_confirm_active() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.89%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.89%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.84%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.89%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaCrítica (9.8)0.80%—Neutrinolabs XrdpDebian Linux9/12/202217/6/2026
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this issue. Users are advised to upgrade.
ModificadaMedia (4.3)0.72%—Notrinoserp23/8/202217/6/2026
Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7.
ModificadaCrítica (9.8)0.91%—Notrinoserp22/8/202217/6/2026
Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.
ModificadaAlta (8.8)1.3%—Notrinoserp21/8/202217/6/2026
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages,…
ModificadaMedia (5.4)0.65%—Notrinoserp17/8/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7.
ModificadaCrítica (9.8)3.3%💥 PoCBaicells Nova436q FirmwareBaicells Neutrino 430 Firmware30/3/202217/6/2026
Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)
ModificadaAlta (7.8)0.49%—Neutrinolabs XrdpFedoraproject Fedora7/2/202217/6/2026
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and…
ModificadaAlta (7.8)2.4%—Neutrinolabs Xrdp30/6/202017/6/2026
The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to…
ModificadaAlta (7.5)1.1%—Intel Centrino Firmware12/9/201817/6/2026
A STOP error (BSoD) in the ibtfltcoex.sys driver for Intel Centrino Wireless N and Intel Centrino Advanced N adapters may allow an unauthenticated user to potentially send a malformed L2CAP Connection Request is sent to the Intel Bluetooth device via the network.
ModificadaAlta (8.4)0.41%—Neutrinolabs XrdpDebian Linux23/11/201717/6/2026
The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted input stream.
Orbitaley — Vulnerabilidades