Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

838 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.2%—Thalesgroup Safenet Keysecure16/6/20219/7/2026
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked.
ModificadaAlta (7.3)1.1%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+183/5/202117/6/2026
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
ModificadaMedia (5.4)1.3%—Safe FME Server28/4/202117/6/2026
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.
ModificadaMedia (6.1)1.2%—Safe FME Server28/4/202117/6/2026
Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login page. The XSS is executed when an administrator accesses the logs.
ModificadaCrítica (9.8)3.4%—Manta Safe-obj26/4/202117/6/2026
Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)3.3%—Safe-flat Project Safe-flat26/4/202117/6/2026
Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaMedia (5.5)0.16%—Bitdefender Safepay12/4/202117/6/2026
An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories. This issue affects: Bitdefender Safepay versions prior to 25.0.7.29.
ModificadaAlta (7.1)72%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the…
ModificadaAlta (8.3)73%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific…
ModificadaCrítica (9.8)8.2%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class. The issue results from the lack of proper…
ModificadaAlta (8.8)65%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the…
ModificadaAlta (7.1)74%—Netgear Prosafe Network Management System29/3/202117/6/2026
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the…
ModificadaAlta (7.8)0.38%—Utimaco Block-safe FirmwareUtimaco Cryptoserver CP5 FirmwareUtimaco Cryptoserver CP5 Vs-nfd FirmwareUtimaco Paymentserver Firmware+218/3/202117/6/2026
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak…
ModificadaMedia (5.5)0.62%—Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+153/3/202117/6/2026
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
ModificadaAlta (7.5)1.5%💥 PoCChainsafe Ethermint8/2/202117/6/2026
Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing cycle, Storage changes caused by a failed transaction are improperly reserved in memory. Although the bad storage cache data will be…
ModificadaAlta (7.5)1.3%—Chainsafe Ethermint8/2/202117/6/2026
Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is further written to persistent store at the Endblock stage, which may be utilized to build honeypot contracts.
ModificadaAlta (7.5)1.3%—Chainsafe Ethermint8/2/202117/6/2026
Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch,…
ModificadaAlta (7.5)1.1%—Chainsafe Ethermint8/2/202117/6/2026
Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application.
ModificadaMedia (5)0.91%—Oracle Argus Safety20/1/202117/6/2026
Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Letters). The supported version that is affected is 8.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Safety. While the vulnerability is in…
ModificadaMedia (6.1)0.97%—Oracle Argus Safety20/1/202117/6/2026
Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Case Form, Local Affiliate Form). The supported version that is affected is 8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Argus Safety.…
ModificadaAlta (7.8)0.58%—Safervpn12/1/202117/6/2026
SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572.
ModificadaMedia (4.2)0.20%—Ftsafe K13Ftsafe K21Ftsafe K40Ftsafe K9+417/1/202117/6/2026
An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was…
ModificadaAlta (7.5)2.2%—Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Http ServerOracle Security Service+116/12/202017/6/2026
Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems.
ModificadaMedia (5.8)1.3%—Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Weblogic Server Proxy Plug-in16/12/202017/6/2026
Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to modify and corrupt the encrypted data.
ModificadaMedia (4.6)0.41%—Lock Password Manager Safe APP Project Lock Password Manager Safe APP30/11/202017/6/2026
The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user.
Orbitaley — Vulnerabilidades