Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (10) | 2.2% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain… | |
| Modificada | Crítica (9.9) | 1.1% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+5 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software… | |
| Modificada | Alta (8.6) | 1.4% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices… | |
| Modificada | Crítica (10) | 2.7% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Crítica (10) | 4.9% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+5 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X,… | |
| Modificada | Crítica (10) | 1.6% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to… | |
| Modificada | Crítica (9.8) | 37% | 💥 Exploit | Zohocorp Manageengine Desktop CentralZohocorp Manageengine Desktop Central Managed Service Providers | 17/1/2020 | 17/6/2026 | Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter. | |
| Modificada | Media (5.3) | 2.4% | — | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications BRM - Elastic Charging EngineOracle Communications Diameter Signaling Router+23 | 17/1/2020 | 17/6/2026 | Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and… | |
| Modificada | Alta (7.5) | 89% | 💥 PoC | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+29 | 17/1/2020 | 17/6/2026 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. | |
| Modificada | Media (5.3) | 2.5% | — | NTPF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+21 | 8/1/2020 | 17/6/2026 | An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information. | |
| Modificada | Media (5.5) | 0.30% | — | F5 Big-iq Centralized ManagementF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+12 | 23/12/2019 | 17/6/2026 | On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions 7.0.0, 6.0.0-6.1.0, and 5.0.0-5.4.0, iWorkflow version 2.3.0, and Enterprise Manager version 3.1.1, authenticated users granted TMOS Shell (tmsh) privileges are able access objects on the file system… | |
| Modificada | Media (4.3) | 0.70% | — | F5 Big-iq Centralized ManagementF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+10 | 23/12/2019 | 17/6/2026 | On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and 5.2.0-5.4.0, a user is able to obtain the secret that was being used to encrypt a BIG-IP UCS backup file while sending SNMP query to the BIG-IP or BIG-IQ system,… | |
| Modificada | Media (5.3) | 1.6% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) contains an authentication bypass vulnerability. A remote attacker with network access to the CCS server could exploit this vulnerability to read data… | |
| Modificada | Media (5.5) | 0.25% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), Control Center Server (CCS) (All versions >= V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0). Both the SiVMS/SiNVR Video Server and the Control Center Server (CCS)… | |
| Modificada | Crítica (9.8) | 2.7% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A remote attacker with network access to the… | |
| Modificada | Media (6.5) | 2.6% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains a directory traversal vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An authenticated remote attacker with network access to… | |
| Modificada | Crítica (9.8) | 2.5% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. A remote attacker with network access to the CCS… | |
| Modificada | Media (4.9) | 0.86% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges for the web interface could be able to… | |
| Modificada | Alta (7.5) | 0.74% | — | Decentralized Anonymous Payment System Project Decentralized Anonymous Payment SystemPivx Private Instant Verified Transactions | 4/12/2019 | 17/6/2026 | An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak signature scheme design that would allow the reuse of signatures in some cases (or… | |
| Modificada | Media (4.3) | 0.41% | — | Dash CoreOfficialdapscoin Decentralized Anonymous Payment SystemPivx Private Instant Verified Transactions | 4/12/2019 | 17/6/2026 | An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can possibly leak their IP address and the fact… | |
| Modificada | Crítica (9.4) | 1.1% | — | F5 Big-ip Application Security ManagerF5 Big-iq Centralized ManagementF5 Enterprise ManagerF5 Iworkflow | 27/11/2019 | 17/6/2026 | On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, an attacker with access to the device communication between the BIG-IP ASM Central Policy Builder and the BIG-IQ/Enterprise Manager/F5 iWorkflow will be able to… | |
| Modificada | Media (6.1) | 1.1% | — | Sandline Centraleyezer | 18/11/2019 | 17/6/2026 | Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to download a CISO Report template, the script is loaded. | |
| Modificada | Media (6.1) | 0.91% | — | Sandline Centraleyezer | 18/11/2019 | 17/6/2026 | Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section. | |
| Modificada | Crítica (9.8) | 2.0% | — | Sandline Centraleyezer | 18/11/2019 | 17/6/2026 | Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side. | |
| Modificada | Media (5.5) | 0.65% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+12 | 15/11/2019 | 17/6/2026 | The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) attack. |