Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.6% | — | Synology Safeaccess | 30/11/2020 | 17/6/2026 | SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter. | |
| Modificada | Media (4.8) | 5.2% | — | Synology Safeaccess | 30/11/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter. | |
| Modificada | Crítica (9.8) | 1.4% | — | Safetydance Project Safetydance | 2/10/2020 | 17/6/2026 | All versions of package safetydance are vulnerable to Prototype Pollution via the set function. | |
| Modificada | Alta (8.1) | 1.4% | — | Safervpn | 18/9/2020 | 17/6/2026 | SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed. | |
| Modificada | Media (5.7) | 1.3% | 💥 PoC | Health Covidsafe | 9/9/2020 | 17/6/2026 | In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public Bluetooth address of the victim's phone without authorisation,… | |
| Modificada | Crítica (9.8) | 1.9% | — | Safe-object2 Project Safe-object2 | 1/9/2020 | 17/6/2026 | All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function. | |
| Modificada | Crítica (9.8) | 1.4% | — | Safe-eval Project Safe-eval | 21/8/2020 | 17/6/2026 | This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine. | |
| Modificada | Media (6.7) | 0.55% | — | Trendmicro Antivirus ToolkitTrendmicro Apex ONETrendmicro Deep SecurityTrendmicro Officescan+8 | 5/8/2020 | 17/6/2026 | An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code… | |
| Modificada | Alta (8.1) | 3.1% | — | F-secure Safe | 23/6/2020 | 17/6/2026 | An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine. | |
| Modificada | Alta (8.1) | 2.8% | — | F-secure Safe | 23/6/2020 | 17/6/2026 | An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already… | |
| Modificada | Media (5.3) | 1.0% | — | Health Covidsafe | 18/5/2020 | 17/6/2026 | COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and potentially identification of the owner's name. | |
| Modificada | Media (5.3) | 0.69% | — | Health Covidsafe | 18/5/2020 | 17/6/2026 | Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identification of devices, especially less common phone models or those in low-density situations. | |
| Modificada | Alta (7.5) | 1.9% | — | Health Covidsafe | 18/5/2020 | 17/6/2026 | Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scanning for their advertising beacons. | |
| Modificada | Alta (7.5) | 1.6% | — | Health Covidsafe | 18/5/2020 | 17/6/2026 | Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re-identify an Android device running COVIDSafe. | |
| Modificada | Crítica (9.8) | 5.1% | 💥 PoC | Alberta AbtracetogetherHealth CovidsafeTracetogether | 18/5/2020 | 17/6/2026 | OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used. | |
| Modificada | Media (6.5) | 1.4% | 💥 PoC | Alberta AbtracetogetherGOV Protego SafeHealth CovidsafeTracetogether | 14/5/2020 | 17/6/2026 | The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether… | |
| Modificada | Media (4.6) | 0.39% | — | Simplisafe SS3 Firmware | 2/5/2020 | 17/6/2026 | Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system. | |
| Modificada | Crítica (9.8) | 2.3% | — | ABB 800xa SystemABB Compact HMIABB Control Builder Safe | 29/4/2020 | 17/6/2026 | For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony… | |
| Modificada | Alta (7.5) | 1.5% | — | ABB 800xa SystemABB Compact HMIABB Control Builder Safe | 29/4/2020 | 17/6/2026 | For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony… | |
| Modificada | Alta (7.5) | 1.2% | — | ABB 800xa SystemABB Compact HMIABB Control Builder Safe | 29/4/2020 | 17/6/2026 | For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony… | |
| Modificada | Alta (7.8) | 0.37% | — | ABB 800xa SystemABB Compact HMIABB Control Builder Safe | 29/4/2020 | 17/6/2026 | For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony… | |
| Modificada | Media (4.1) | 0.37% | — | Pyup Safety | 23/3/2020 | 17/6/2026 | The command-line "safety" package for Python has a potential security issue. There are two Python characteristics that allow malicious code to “poison-pill” command-line Safety package detection routines by disguising, or obfuscating, other malicious or non-secure packages. This vulnerability is considered to be of… | |
| Modificada | Alta (7.2) | 3.2% | — | Netgear Prosafe Wc9500 FirmwareNetgear Prosafe Wc7600 FirmwareNetgear Prosafe Wc7520 Firmware | 23/3/2020 | 17/6/2026 | NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php. | |
| Modificada | Crítica (9.8) | 5.0% | — | Safescan Ta-8010 FirmwareSafescan Ta-8015 FirmwareSafescan Ta-8020 FirmwareSafescan Ta-8025 Firmware+3 | 13/3/2020 | 17/6/2026 | Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API. | |
| Modificada | Alta (7.5) | 2.1% | — | Safescan Timemoto Tm-616 FirmwareSafescan Ta-8035 FirmwareSafescan Ta-8010 FirmwareSafescan Ta-8015 Firmware+3 | 2/3/2020 | 17/6/2026 | Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API. |