Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.43%—Siemens Sinema Remote Connect Server13/9/201917/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web application are not protected against Cross Site Request Forgery (CSRF) attacks. The security vulnerability could be exploited by an attacker that is able to trigger requests of a logged-in user to the…
ModificadaMedia (4.3)0.83%—Siemens Sinema Remote Connect Server13/9/201917/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should only be accessible by a privileged user can also be accessed by a non-privileged user. The security vulnerability could be exploited by an attacker with network access and valid credentials for the web…
ModificadaCrítica (9.8)1.5%—Siemens Sinema Remote Connect Server13/9/201917/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. The…
ModificadaCrítica (9.8)5.8%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+913/9/201917/6/2026
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
ModificadaAlta (7.5)3.2%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+913/9/201917/6/2026
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
ModificadaAlta (7.8)1.1%—Checkpoint Capsule Docs Standalone ClientCheckpoint Endpoint SecurityCheckpoint Remote Access Clients29/8/201917/6/2026
Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the…
ModificadaMedia (6.7)0.44%—Cisco Remote PHY 120 FirmwareCisco Remote PHY 220 FirmwareCisco Remote PHY Shelf 7200 FirmwareCisco Cbr-8 Firmware21/8/201917/6/2026
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid…
ModificadaAlta (7.8)0.35%—Intel Remote Displays SDK19/8/201917/6/2026
Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8)71%💥 PoCMicrosoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 11 21h2Microsoft Windows 7+615/7/201917/6/2026
A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
ModificadaCrítica (9.8)1.2%—Checkpoint Jumbo Hotfix FOR Endpoint Security ServerCheckpoint Endpoint Security Server PackageCheckpoint Smartconsole FOR Endpoint Security ServerCheckpoint Endpoint Security Clients+220/6/201917/6/2026
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.
ModificadaMedia (4.4)0.97%—Checkpoint Endpoint Security ClientsCheckpoint Remote Access ClientsCheckpoint Capsule Docs20/6/201917/6/2026
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary,…
ModificadaAlta (7.4)26%—Solarwinds Dameware Mini Remote Control7/6/201917/6/2026
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.
ModificadaAlta (7.4)1.6%—Dameware Remote Mini Control7/6/201917/6/2026
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating CltDHPubKeyLen during key negotiation, which could crash the application or leak sensitive information.
ModificadaAlta (8.8)1.3%—Logitech R700 Laser Presentation Remote Firmware7/6/201917/6/2026
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system is unattended.…
ModificadaAlta (7.5)18%—Dameware Remote Mini Control7/6/201917/6/2026
Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the server not properly validating RsaPubKeyLen during key negotiation. An unauthenticated remote attacker can cause a heap buffer overflow by specifying a large RsaPubKeyLen, which could cause a denial of…
ModificadaCrítica (9.9)1.9%—Jenkins Pipeline Remote Loader31/5/201917/6/2026
Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.
ModificadaAlta (7.5)19%💥 ExploitSolarwinds Dameware Mini Remote Control2/5/201917/6/2026
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
ModificadaAlta (8.8)1.3%—Siemens Sinema Remote Connect Server17/4/201917/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking of user permissions, an attacker may access URLs that require special authorization. An attacker must have access to a low privileged account in order to exploit the vulnerability.
ModificadaCrítica (9.1)1.2%—HP Remote Graphics Software27/3/201917/6/2026
A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.
ModificadaAlta (7.5)0.84%—Abus Secvest Wireless Alarm System Fuaa50000 FirmwareAbus Secvest Wireless Remote Control Fube50014 FirmwareAbus Secvest Wireless Remote Control Fube50015 Firmware27/3/201917/6/2026
Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Secvest wireless remote control (FUBE50014 or FUBE50015) relative to its controlled Secvest wireless alarm system FUAA50000 3.01.01, so that sent commands by the remote control are not accepted anymore.
ModificadaCrítica (9.8)2.1%—Abus Secvest Wireless Alarm System Fuaa50000 FirmwareAbus Secvest Wireless Remote Control Fube50014 FirmwareAbus Secvest Wireless Remote Control Fube50015 Firmware27/3/201917/6/2026
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict valid future rolling codes, and can thus remotely control the alarm system in an unauthorized way.
ModificadaMedia (6.5)0.64%—Abus Secvest Wireless Alarm System Fuaa50000 FirmwareAbus Secvest Wireless Remote Control Fube50014 FirmwareAbus Secvest Wireless Remote Control Fube50015 Firmware27/3/201917/6/2026
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, an attacker is able to eavesdrop sensitive data as cleartext (for instance, the current rolling code state).
ModificadaCrítica (9.8)13%—Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+126/2/201917/6/2026
libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent…
ModificadaAlta (7.5)5.4%💥 PoCHaxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+66/2/201917/6/2026
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a…
ModificadaMedia (6.5)0.60%—Cybozu Remote Service Manager9/1/201917/6/2026
Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate.
Orbitaley — Vulnerabilidades