Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.37% | — | Visam Vbase EditorVisam Vbase Web-remote | 3/4/2020 | 17/6/2026 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application. | |
| Modificada | Alta (7.5) | 1.1% | — | Visam Vbase EditorVisam Vbase Web-remote | 3/4/2020 | 17/6/2026 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass authentication of the HTML5 HMI web interface. | |
| Modificada | Alta (7.8) | 0.25% | — | Visam Vbase EditorVisam Vbase Web-remote | 3/4/2020 | 17/6/2026 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a local attacker to bypass the password-protected mechanism through brute-force attacks, cracking techniques, or overwriting the password hash. | |
| Modificada | Crítica (9.8) | 2.6% | — | Visam Vbase EditorVisam Vbase Web-remote | 3/4/2020 | 17/6/2026 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of arbitrary code. | |
| Modificada | Crítica (9.8) | 4.2% | — | Git-add-remote Project Git-add-remote | 2/4/2020 | 17/6/2026 | git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument. | |
| Modificada | Crítica (9.8) | 2.5% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+10 | 26/3/2020 | 17/6/2026 | CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow. | |
| Modificada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Remote Access Plus | 19/3/2020 | 17/6/2026 | Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover. | |
| Analizada | Alta (7.8) | 7.3% | ⚠ Explotación activa💥 Exploit | Vmware FusionVmware Horizon ClientVmware Remote Console | 17/3/2020 | 17/6/2026 | VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user… | |
| Modificada | Alta (7.5) | 4.4% | — | Nagios Remote Plug IN ExecutorFedoraproject Fedora | 16/3/2020 | 17/6/2026 | Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call. | |
| Modificada | Alta (7.3) | 1.6% | — | Nagios Remote Plug IN ExecutorFedoraproject Fedora | 16/3/2020 | 17/6/2026 | Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection. | |
| Modificada | Alta (7.8) | 0.39% | — | Vmware Horizon ClientVmware Remote ConsoleVmware Workstation | 16/3/2020 | 17/6/2026 | For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the… | |
| Modificada | Crítica (9.8) | 2.7% | — | Docker-compose-remote-api Project Docker-compose-remote-api | 15/3/2020 | 17/6/2026 | docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization. | |
| Modificada | Media (5.5) | 4.7% | — | Microsoft Remote Desktop Connection Manager | 12/3/2020 | 17/6/2026 | An information disclosure vulnerability exists in the Remote Desktop Connection Manager (RDCMan) application when it improperly parses XML input containing a reference to an external entity, aka 'Remote Desktop Connection Manager Information Disclosure Vulnerability'. | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Remote PHY 120 FirmwareCisco Remote PHY 220 FirmwareCisco Remote PHY Shelf 7200 Firmware | 4/3/2020 | 17/6/2026 | A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists because the affected software does not properly sanitize user-supplied input. An attacker who has valid… | |
| Modificada | Media (4.3) | 1.4% | — | Zohocorp Manageengine Remote Access Plus | 17/2/2020 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the… | |
| Modificada | Media (4.3) | 1.4% | — | Zohocorp Manageengine Remote Access Plus | 31/1/2020 | 17/6/2026 | An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description… | |
| Modificada | Alta (7.5) | 7.8% | — | Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+20 | 21/1/2020 | 17/6/2026 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. | |
| Modificada | Alta (7.5) | 5.6% | — | Xmlsoft Libxml2Debian LinuxOracle Real User Experience InsightFedoraproject Fedora+8 | 24/12/2019 | 17/6/2026 | xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. | |
| Modificada | Crítica (9.8) | 1.9% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+10 | 20/11/2019 | 17/6/2026 | CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. | |
| Modificada | Media (5.4) | 0.53% | — | Comtech H8 Heights Remote Gateway Firmware | 17/10/2019 | 17/6/2026 | Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field. | |
| Modificada | Alta (8.8) | 0.30% | — | Vmware HorizonVmware Remote ConsoleVmware WorkstationVmware Fusion+1 | 10/10/2019 | 17/6/2026 | ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5. | |
| Modificada | Crítica (9.8) | 5.1% | 💥 PoC | Solarwinds Dameware Mini Remote Control | 8/10/2019 | 17/6/2026 | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System… | |
| Modificada | Crítica (9.8) | 3.1% | — | Intelliantech Remote Access | 7/10/2019 | 17/6/2026 | Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field. | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins Call Remote JOB | 25/9/2019 | 17/6/2026 | Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Baja (2.7) | 0.55% | — | Siemens Sinema Remote Connect Server | 13/9/2019 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administrative privileges can obtain the hash of a connected device's password. The security vulnerability could be exploited by an attacker with network access to the SINEMA Remote Connect Server and… |