Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.2% | — | Thalesgroup Safenet Keysecure | 16/6/2021 | 9/7/2026 | SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. | |
| Modificada | Alta (7.3) | 1.1% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+18 | 3/5/2021 | 17/6/2026 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages. | |
| Modificada | Media (5.4) | 1.3% | — | Safe FME Server | 28/4/2021 | 17/6/2026 | Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs. | |
| Modificada | Media (6.1) | 1.2% | — | Safe FME Server | 28/4/2021 | 17/6/2026 | Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login page. The XSS is executed when an administrator accesses the logs. | |
| Modificada | Crítica (9.8) | 3.4% | — | Manta Safe-obj | 26/4/2021 | 17/6/2026 | Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Crítica (9.8) | 3.3% | — | Safe-flat Project Safe-flat | 26/4/2021 | 17/6/2026 | Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| Modificada | Media (5.5) | 0.16% | — | Bitdefender Safepay | 12/4/2021 | 17/6/2026 | An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories. This issue affects: Bitdefender Safepay versions prior to 25.0.7.29. | |
| Modificada | Alta (7.1) | 72% | — | Netgear Prosafe Network Management System | 29/3/2021 | 17/6/2026 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the… | |
| Modificada | Alta (8.3) | 73% | — | Netgear Prosafe Network Management System | 29/3/2021 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific… | |
| Modificada | Crítica (9.8) | 8.2% | — | Netgear Prosafe Network Management System | 29/3/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class. The issue results from the lack of proper… | |
| Modificada | Alta (8.8) | 65% | — | Netgear Prosafe Network Management System | 29/3/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the… | |
| Modificada | Alta (7.1) | 74% | — | Netgear Prosafe Network Management System | 29/3/2021 | 17/6/2026 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 0.38% | — | Utimaco Block-safe FirmwareUtimaco Cryptoserver CP5 FirmwareUtimaco Cryptoserver CP5 Vs-nfd FirmwareUtimaco Paymentserver Firmware+2 | 18/3/2021 | 17/6/2026 | Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak… | |
| Modificada | Media (5.5) | 0.62% | — | Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+15 | 3/3/2021 | 17/6/2026 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | |
| Modificada | Alta (7.5) | 1.5% | 💥 PoC | Chainsafe Ethermint | 8/2/2021 | 17/6/2026 | Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing cycle, Storage changes caused by a failed transaction are improperly reserved in memory. Although the bad storage cache data will be… | |
| Modificada | Alta (7.5) | 1.3% | — | Chainsafe Ethermint | 8/2/2021 | 17/6/2026 | Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is further written to persistent store at the Endblock stage, which may be utilized to build honeypot contracts. | |
| Modificada | Alta (7.5) | 1.3% | — | Chainsafe Ethermint | 8/2/2021 | 17/6/2026 | Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes with ethereum for compatibility, a verified signature in ethereum is still valid in ethermint with the same msg content and chainIDEpoch,… | |
| Modificada | Alta (7.5) | 1.1% | — | Chainsafe Ethermint | 8/2/2021 | 17/6/2026 | Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay the transaction through the application. | |
| Modificada | Media (5) | 0.91% | — | Oracle Argus Safety | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Letters). The supported version that is affected is 8.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Safety. While the vulnerability is in… | |
| Modificada | Media (6.1) | 0.97% | — | Oracle Argus Safety | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Case Form, Local Affiliate Form). The supported version that is affected is 8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Argus Safety.… | |
| Modificada | Alta (7.8) | 0.58% | — | Safervpn | 12/1/2021 | 17/6/2026 | SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572. | |
| Modificada | Media (4.2) | 0.20% | — | Ftsafe K13Ftsafe K21Ftsafe K40Ftsafe K9+41 | 7/1/2021 | 17/6/2026 | An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was… | |
| Modificada | Alta (7.5) | 2.2% | — | Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Http ServerOracle Security Service+1 | 16/12/2020 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems. | |
| Modificada | Media (5.8) | 1.3% | — | Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Weblogic Server Proxy Plug-in | 16/12/2020 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to modify and corrupt the encrypted data. | |
| Modificada | Media (4.6) | 0.41% | — | Lock Password Manager Safe APP Project Lock Password Manager Safe APP | 30/11/2020 | 17/6/2026 | The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user. |