Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 1.1% | — | Undefsafe Project Undefsafe | 18/2/2020 | 17/6/2026 | undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. | |
| Modificada | Media (5.5) | 0.36% | — | Simplisafe SS3 Firmware | 13/2/2020 | 17/6/2026 | Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated attacker to modify the Wi-Fi network the base station connects to. | |
| Modificada | Media (5.9) | 0.60% | — | Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+36 | 7/2/2020 | 17/6/2026 | The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,… | |
| Modificada | Crítica (9.8) | 6.7% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Crítica (9.8) | 4.2% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Crítica (9.8) | 4.2% | — | Yokogawa Centum CS 1000 FirmwareYokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry FirmwareYokogawa Centum VP Firmware+17 | 5/2/2020 | 17/6/2026 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and… | |
| Modificada | Media (6.5) | 1.9% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+11 | 24/1/2020 | 17/6/2026 | CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition. | |
| Modificada | Media (4.6) | 0.39% | — | Simplisafe SS3 Firmware | 16/1/2020 | 17/6/2026 | Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system. | |
| Modificada | Alta (7.1) | 0.71% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus ReadystartSiemens Nucleus Safetycert+22 | 16/1/2020 | 17/6/2026 | A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8.2 < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8.2… | |
| Modificada | Alta (7.8) | 0.48% | — | Safend Data Protector Agent | 13/1/2020 | 16/6/2026 | A Privilege Escalation vulnerability exists in the unquoted Service Binary in SDPAgent or SDBAgent in Safend Data Protector Agent 3.4.5586.9772, which could let a local malicious user obtain privileges. | |
| Modificada | Alta (7.8) | 0.48% | — | Safend Data Protector Agent | 13/1/2020 | 16/6/2026 | A Privilege Escalation vulnerability exists in the SDBagent service in Safend Data Protector Agent 3.4.5586.9772, which could let a local malicious user obtain privileges. | |
| Modificada | Media (6.1) | 0.48% | — | Safend Data Protector Agent | 13/1/2020 | 16/6/2026 | An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, which could let a malicious user decrypt and potentially change the Safend security policies applied to the machine. | |
| Modificada | Media (5.3) | 2.5% | — | NTPF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+21 | 8/1/2020 | 17/6/2026 | An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information. | |
| Modificada | Crítica (9.8) | 2.6% | — | Safer-eval Project Safer-eval | 6/12/2019 | 17/6/2026 | safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError. | |
| Modificada | Alta (7.5) | 2.6% | — | 10up Safe SVG | 11/11/2019 | 17/6/2026 | A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes. | |
| Modificada | Alta (7.5) | 2.6% | — | 10up Safe SVG | 11/11/2019 | 17/6/2026 | A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (8.8) | 1.8% | — | 360 Safe Router P0 Firmware360 Safe Router P1 Firmware360 Safe Router P2 Firmware360 Safe Router P3 Firmware+1 | 4/11/2019 | 17/6/2026 | A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897. | |
| Modificada | Media (4.6) | 0.39% | — | Archos Safe-t | 2/11/2019 | 17/6/2026 | On Archos Safe-T devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior… | |
| Modificada | Alta (8.8) | 0.66% | — | IBM Maximo FOR OIL AND GASIBM Maximo Health, Safety AND Environment Manager | 29/10/2019 | 17/6/2026 | After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allowed to access. IBM X-Force ID: 165948. | |
| Modificada | Crítica (9.9) | 2.9% | 💥 PoC | Safer-eval Project Safer-eval | 15/10/2019 | 17/6/2026 | safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code. | |
| Modificada | Crítica (9.9) | 1.8% | — | Safer-eval Project Safer-eval | 15/10/2019 | 17/6/2026 | safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code. | |
| Modificada | Media (4.9) | 0.60% | — | Dell Bsafe Crypto-c-micro-editionEMC RSA Bsafe Crypto-c | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A malicious remote user could potentially exploit this vulnerability to extract information leaving data at… | |
| Modificada | Alta (7.5) | 1.4% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteEMC RSA Bsafe Crypto-c | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) versions prior to 4.1.6.1 (in 4.1.x) and versions prior to 4.3.3 (4.2.x and 4.3.x) are vulnerable to an Information Exposure Through Timing… | |
| Modificada | Alta (7.5) | 1.4% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suite | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition versions prior to 4.1.4 and RSA Micro Edition Suite versions prior to 4.4 are vulnerable to an Information Exposure Through Timing Discrepancy. A malicious remote user could potentially exploit this vulnerability to extract information leaving data at risk of exposure. |