Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%—Cybelesoft Thinfinity Remote Desktop Workstation6/10/201717/6/2026
Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to download arbitrary files via a .. (dot dot) in an unspecified parameter.
ModificadaMedia (5.3)1.8%—EMC Secure Remote Services14/6/201717/6/2026
EMC ESRS VE 3.18 or earlier contains Authentication Bypass that could potentially be exploited by malicious users to compromise the affected system.
ModificadaMedia (5.3)2.7%—Cisco Remote Expert Manager22/5/201717/6/2026
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Temporary File information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when responding…
ModificadaMedia (5.3)2.7%—Cisco Remote Expert Manager22/5/201717/6/2026
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Order information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when responding to HTTP…
ModificadaMedia (5.3)2.7%—Cisco Remote Expert Manager22/5/201717/6/2026
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Temporary Directory information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when…
ModificadaMedia (5.3)2.7%—Cisco Remote Expert Manager22/5/201717/6/2026
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when responding to HTTP requests…
ModificadaMedia (5.3)2.7%—Cisco Remote Expert Manager22/5/201717/6/2026
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Directory information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when…
ModificadaMedia (5.3)2.7%—Cisco Remote Expert Manager22/5/201717/6/2026
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not sufficiently protect sensitive data when responding to HTTP requests…
ModificadaAlta (7.5)2.4%—Cisco Remote Expert Manager22/5/201717/6/2026
A vulnerability in the TCP connection handling functionality of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to disable TCP ports and cause a denial of service (DoS) condition on an affected system. The vulnerability is due to a lack of rate-limiting functionality in the…
ModificadaAlta (7.5)1.6%—IBM Bigfix Remote Control3/5/201717/6/2026
IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID: 5512.
ModificadaMedia (4.2)0.45%—Cybozu Remote Service Manager28/4/201717/6/2026
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.
ModificadaMedia (6.1)1.2%—Dell Integrated Remote Access Controller Firmware10/4/201717/6/2026
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
ModificadaAlta (8.8)2.0%—Dell Integrated Remote Access Controller Firmware10/4/201717/6/2026
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.
ModificadaCrítica (9.8)1.4%—Dell Integrated Remote Access Controller Firmware10/4/201717/6/2026
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
ModificadaCrítica (9.8)2.7%—Dell Integrated Remote Access Controller Firmware10/4/201717/6/2026
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input.
ModificadaCrítica (9.8)2.7%—Dell Integrated Remote Access Controller Firmware10/4/201717/6/2026
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
ModificadaAlta (7.8)1.1%—Dell Integrated Remote Access Controller Firmware10/4/201717/6/2026
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
ModificadaCrítica (9.8)7.1%💥 ExploitDell Sonicwall Secure Remote Access Server22/2/201717/6/2026
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application…
ModificadaCrítica (9.8)12%💥 ExploitDell Sonicwall Secure Remote Access Server22/2/201717/6/2026
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server's internal…
ModificadaCrítica (9.8)23%💥 ExploitDell Sonicwall Secure Remote Access Server22/2/201717/6/2026
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system.…
ModificadaMedia (5.5)0.84%—Netop Remote Control9/1/201717/6/2026
Stack-based buffer overflow vulnerability in Netop Remote Control versions 11.53, 12.21 and prior. The affected module in the Guest client is the "Import to Phonebook" option. When a specially designed malicious file containing special characters is loaded, the overflow occurs. 12.51 is the fixed version. The Support…
ModificadaAlta (8.8)0.63%—IBM Bigfix Remote Control30/11/201617/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
ModificadaBaja (3.7)1.6%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.
ModificadaBaja (3.7)0.66%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
ModificadaMedia (6.5)1.1%—IBM Bigfix Remote Control30/11/201617/6/2026
SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.