Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.9% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors. | |
| Modificada | Alta (8.1) | 1.7% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.3% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors. | |
| Modificada | Media (5.5) | 0.44% | — | Dell EMC Secure Remote Services | 18/10/2018 | 17/6/2026 | Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the… | |
| Modificada | Alta (7.8) | 0.37% | — | EMC Secure Remote Services | 18/10/2018 | 17/6/2026 | Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-readable permissions that could allow an authenticated malicious user to utilize the file contents to potentially elevate their privileges. | |
| Modificada | Alta (7.8) | 0.37% | — | EMC Secure Remote Services | 18/10/2018 | 17/6/2026 | Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the… | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco Remote | 5/10/2018 | 17/6/2026 | A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to impact traffic passing through a device, potentially causing a denial of service (DoS) condition. The vulnerability is due to the affected software not validating and… | |
| Modificada | Alta (7.8) | 1.7% | 💥 Exploit | Solarwinds Dameware Mini Remote Control | 7/9/2018 | 17/6/2026 | SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow. | |
| Modificada | Alta (7.5) | 32% | — | Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+47 | 6/9/2018 | 17/6/2026 | The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered… | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Alta (8.8) | 2.3% | — | IBM Endpoint Manager FOR Remote ControlIBM Tivoli Remote Control | 27/4/2018 | 16/6/2026 | IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309. | |
| Modificada | Alta (7.8) | 0.29% | — | Intel Remote Keyboard Mobile APP | 3/4/2018 | 17/6/2026 | Escalation of privilege in all versions of the Intel Remote Keyboard allows a local attacker to inject keystrokes into another remote keyboard session. | |
| Modificada | Crítica (9.8) | 1.1% | — | Intel Remote Keyboard Mobile APP | 3/4/2018 | 17/6/2026 | Escalation of privilege in all versions of the Intel Remote Keyboard allows a network attacker to inject keystrokes as a local user. | |
| Modificada | Alta (7.8) | 0.37% | — | Intel Remote Keyboard Mobile APP | 3/4/2018 | 17/6/2026 | Escalation of privilege in all versions of the Intel Remote Keyboard allows an authorized local attacker to execute arbitrary code as a privileged user. | |
| Modificada | Media (4.8) | 0.32% | — | IBM Bigfix Remote Control | 29/3/2018 | 17/6/2026 | IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197. | |
| Modificada | Alta (8.8) | 1.9% | — | IBM Endpoint Manager FOR Remote Control | 29/3/2018 | 17/6/2026 | The on-demand plugin in IBM Endpoint Manager for Remote Control 9.0.1 and 9.1.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. IBM X-Force ID: 105196. | |
| Modificada | Media (5.9) | 0.66% | — | IBM Bigfix Remote Control | 27/3/2018 | 17/6/2026 | IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors. IBM X-Force ID: 105200. | |
| Modificada | Crítica (10) | 2.0% | — | Bomgar Remote Support | 26/3/2018 | 17/6/2026 | Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website… | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service Remote WEB Workplace Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.5) | 2.0% | — | Parallels Remote Application Server | 28/2/2018 | 17/6/2026 | In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness to read arbitrary files from the… | |
| Modificada | Media (6.5) | 1.4% | — | HP Moonshot Remote Console AdministratorHP Integrated Lights-out 2 FirmwareHP Integrated Lights-out 3 FirmwareHP Integrated Lights-out 4 Firmware | 15/2/2018 | 17/6/2026 | A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found. | |
| Modificada | Media (6.7) | 0.31% | — | IBM Bigfix Remote Control | 31/1/2018 | 17/6/2026 | IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912. | |
| Modificada | Crítica (9.1) | 1.2% | — | Ohmibod Remote | 1/12/2017 | 17/6/2026 | The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for search responses from the OhMiBod API server and then editing the username, user_id, and token fields in data/data/com.ohmibod.remote2/shared_prefs/OMB.xml. | |
| Modificada | Alta (7.5) | 0.84% | — | Vibease ChatVibease Wireless Remote Vibrator | 1/12/2017 | 17/6/2026 | The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages with other apps and the PLAIN SASL mechanism to send auth tokens to Vibease servers, which allows remote attackers to obtain user credentials, messages, and other sensitive information by sniffing… | |
| Modificada | Alta (7.8) | 1.3% | — | Beyondtrust Remote Support | 26/10/2017 | 17/6/2026 | The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions. |