Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.37%—Visam Vbase EditorVisam Vbase Web-remote3/4/202017/6/2026
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application.
ModificadaAlta (7.5)1.1%—Visam Vbase EditorVisam Vbase Web-remote3/4/202017/6/2026
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass authentication of the HTML5 HMI web interface.
ModificadaAlta (7.8)0.25%—Visam Vbase EditorVisam Vbase Web-remote3/4/202017/6/2026
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a local attacker to bypass the password-protected mechanism through brute-force attacks, cracking techniques, or overwriting the password hash.
ModificadaCrítica (9.8)2.6%—Visam Vbase EditorVisam Vbase Web-remote3/4/202017/6/2026
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of arbitrary code.
ModificadaCrítica (9.8)4.2%—Git-add-remote Project Git-add-remote2/4/202017/6/2026
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
ModificadaCrítica (9.8)2.5%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+1026/3/202017/6/2026
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
ModificadaAlta (8.8)3.0%—Zohocorp Manageengine Remote Access Plus19/3/202017/6/2026
Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.
AnalizadaAlta (7.8)7.3%⚠ Explotación activa💥 ExploitVmware FusionVmware Horizon ClientVmware Remote Console17/3/202017/6/2026
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user…
ModificadaAlta (7.5)4.4%—Nagios Remote Plug IN ExecutorFedoraproject Fedora16/3/202017/6/2026
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.
ModificadaAlta (7.3)1.6%—Nagios Remote Plug IN ExecutorFedoraproject Fedora16/3/202017/6/2026
Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection.
ModificadaAlta (7.8)0.39%—Vmware Horizon ClientVmware Remote ConsoleVmware Workstation16/3/202017/6/2026
For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the…
ModificadaCrítica (9.8)2.7%—Docker-compose-remote-api Project Docker-compose-remote-api15/3/202017/6/2026
docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.
ModificadaMedia (5.5)4.7%—Microsoft Remote Desktop Connection Manager12/3/202017/6/2026
An information disclosure vulnerability exists in the Remote Desktop Connection Manager (RDCMan) application when it improperly parses XML input containing a reference to an external entity, aka 'Remote Desktop Connection Manager Information Disclosure Vulnerability'.
ModificadaMedia (6.7)0.45%—Cisco Remote PHY 120 FirmwareCisco Remote PHY 220 FirmwareCisco Remote PHY Shelf 7200 Firmware4/3/202017/6/2026
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists because the affected software does not properly sanitize user-supplied input. An attacker who has valid…
ModificadaMedia (4.3)1.4%—Zohocorp Manageengine Remote Access Plus17/2/202017/6/2026
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the…
ModificadaMedia (4.3)1.4%—Zohocorp Manageengine Remote Access Plus31/1/202017/6/2026
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description…
ModificadaAlta (7.5)7.8%—Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+2021/1/202017/6/2026
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
ModificadaAlta (7.5)5.6%—Xmlsoft Libxml2Debian LinuxOracle Real User Experience InsightFedoraproject Fedora+824/12/201917/6/2026
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
ModificadaCrítica (9.8)1.9%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+1020/11/201917/6/2026
CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
ModificadaMedia (5.4)0.53%—Comtech H8 Heights Remote Gateway Firmware17/10/201917/6/2026
Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.
ModificadaAlta (8.8)0.30%—Vmware HorizonVmware Remote ConsoleVmware WorkstationVmware Fusion+110/10/201917/6/2026
ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.
ModificadaCrítica (9.8)5.1%💥 PoCSolarwinds Dameware Mini Remote Control8/10/201917/6/2026
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System…
ModificadaCrítica (9.8)3.1%—Intelliantech Remote Access7/10/201917/6/2026
Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.
ModificadaMedia (6.5)1.0%—Jenkins Call Remote JOB25/9/201917/6/2026
Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaBaja (2.7)0.55%—Siemens Sinema Remote Connect Server13/9/201917/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attacker with network access to the SINEMA Remote Connect Server and…
Orbitaley — Vulnerabilidades