Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.31%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.
ModificadaAlta (7.8)0.28%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
ModificadaCrítica (9.8)1.5%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
ModificadaBaja (1.9)0.27%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.
ModificadaMedia (5.3)1.3%—IBM Bigfix Remote Control30/11/201617/6/2026
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.
ModificadaMedia (6.5)1.3%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerability."
ModificadaAlta (7.3)1.0%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.
ModificadaMedia (5.3)1.6%—IBM Bigfix Remote Control30/11/201617/6/2026
The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.
ModificadaMedia (6.1)1.1%—IBM Bigfix Remote Control30/11/201617/6/2026
Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)2.8%—IBM Bigfix Remote Control30/11/201617/6/2026
Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.
ModificadaMedia (5.3)1.4%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.
ModificadaMedia (5.3)1.5%—IBM Bigfix Remote Control30/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
ModificadaAlta (8.1)1.3%—IBM Bigfix Remote Control25/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a brute-force approach.
ModificadaMedia (4.3)1.0%—IBM Bigfix Remote Control25/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.
ModificadaMedia (5.9)0.81%—IBM Bigfix Remote Control25/11/201617/6/2026
IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
ModificadaMedia (6.4)0.38%—Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic IT Production SuiteSiemens Simatic NET PC Software+1415/11/201617/6/2026
A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7…
ModificadaMedia (6.1)1.6%—Siemens Sinema Remote Connect Server22/7/201617/6/2026
Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (6.5)2.6%—Debian LinuxRemotesensing Libtiff13/4/201617/6/2026
The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cvs-1.tif and libtiff-cvs-2.tif.
ModificadaCrítica (9.8)51%💥 ExploitDameware Mini Remote Control17/3/201617/6/2026
Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.
ModificadaMedia (6.5)63%💥 PoCSophos Unified Threat Management SoftwareOracle LinuxOracle SolarisOpenbsd Openssh+214/1/201617/6/2026
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
ModificadaMedia (4.3)2.0%—EMC Secure Remote Services28/12/201517/6/2026
Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote authenticated users to read log files via a crafted parameter.
ModificadaAlta (7.5)4.8%—Solarwinds Dameware Mini Remote Control17/11/201517/6/2026
Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.
ModificadaBaja (3.7)0.34%—Apple MAC OS XApple Remote Desktop14/11/201516/6/2026
The Remote Desktop full-screen feature in Apple OS X before 10.9 and Apple Remote Desktop before 3.7 sends dialog-box text to a connected remote host upon being woken from sleep, which allows physically proximate attackers to bypass intended access restrictions by entering a command in this box.
ModificadaAlta (9.3)2.5%—EMC Secure Remote Services5/7/201517/6/2026
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.
ModificadaMedia (5.8)0.67%—EMC Secure Remote Services5/7/201517/6/2026
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades