Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

838 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.6%—Synology Safeaccess30/11/202017/6/2026
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
ModificadaMedia (4.8)5.2%—Synology Safeaccess30/11/202017/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Synology SafeAccess before 1.2.3-0234 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) profile parameter.
ModificadaCrítica (9.8)1.4%—Safetydance Project Safetydance2/10/202017/6/2026
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
ModificadaAlta (8.1)1.4%—Safervpn18/9/202017/6/2026
SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.
ModificadaMedia (5.7)1.3%💥 PoCHealth Covidsafe9/9/202017/6/2026
In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public Bluetooth address of the victim's phone without authorisation,…
ModificadaCrítica (9.8)1.9%—Safe-object2 Project Safe-object21/9/202017/6/2026
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
ModificadaCrítica (9.8)1.4%—Safe-eval Project Safe-eval21/8/202017/6/2026
This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.
ModificadaMedia (6.7)0.55%—Trendmicro Antivirus ToolkitTrendmicro Apex ONETrendmicro Deep SecurityTrendmicro Officescan+85/8/202017/6/2026
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code…
ModificadaAlta (8.1)3.1%—F-secure Safe23/6/202017/6/2026
An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.
ModificadaAlta (8.1)2.8%—F-secure Safe23/6/202017/6/2026
An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already…
ModificadaMedia (5.3)1.0%—Health Covidsafe18/5/202017/6/2026
COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and potentially identification of the owner's name.
ModificadaMedia (5.3)0.69%—Health Covidsafe18/5/202017/6/2026
Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identification of devices, especially less common phone models or those in low-density situations.
ModificadaAlta (7.5)1.9%—Health Covidsafe18/5/202017/6/2026
Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scanning for their advertising beacons.
ModificadaAlta (7.5)1.6%—Health Covidsafe18/5/202017/6/2026
Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re-identify an Android device running COVIDSafe.
ModificadaCrítica (9.8)5.1%💥 PoCAlberta AbtracetogetherHealth CovidsafeTracetogether18/5/202017/6/2026
OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used.
ModificadaMedia (6.5)1.4%💥 PoCAlberta AbtracetogetherGOV Protego SafeHealth CovidsafeTracetogether14/5/202017/6/2026
The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether…
ModificadaMedia (4.6)0.39%—Simplisafe SS3 Firmware2/5/202017/6/2026
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system.
ModificadaCrítica (9.8)2.3%—ABB 800xa SystemABB Compact HMIABB Control Builder Safe29/4/202017/6/2026
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony…
ModificadaAlta (7.5)1.5%—ABB 800xa SystemABB Compact HMIABB Control Builder Safe29/4/202017/6/2026
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony…
ModificadaAlta (7.5)1.2%—ABB 800xa SystemABB Compact HMIABB Control Builder Safe29/4/202017/6/2026
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony…
ModificadaAlta (7.8)0.37%—ABB 800xa SystemABB Compact HMIABB Control Builder Safe29/4/202017/6/2026
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony…
ModificadaMedia (4.1)0.37%—Pyup Safety23/3/202017/6/2026
The command-line "safety" package for Python has a potential security issue. There are two Python characteristics that allow malicious code to “poison-pill” command-line Safety package detection routines by disguising, or obfuscating, other malicious or non-secure packages. This vulnerability is considered to be of…
ModificadaAlta (7.2)3.2%—Netgear Prosafe Wc9500 FirmwareNetgear Prosafe Wc7600 FirmwareNetgear Prosafe Wc7520 Firmware23/3/202017/6/2026
NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php.
ModificadaCrítica (9.8)5.0%—Safescan Ta-8010 FirmwareSafescan Ta-8015 FirmwareSafescan Ta-8020 FirmwareSafescan Ta-8025 Firmware+313/3/202017/6/2026
Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.
ModificadaAlta (7.5)2.1%—Safescan Timemoto Tm-616 FirmwareSafescan Ta-8035 FirmwareSafescan Ta-8010 FirmwareSafescan Ta-8015 Firmware+32/3/202017/6/2026
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.
Orbitaley — Vulnerabilidades