Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.31% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session. | |
| Modificada | Alta (7.8) | 0.28% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.5% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. | |
| Modificada | Baja (1.9) | 0.27% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (6.5) | 1.3% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerability." | |
| Modificada | Alta (7.3) | 1.0% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors. | |
| Modificada | Media (5.3) | 1.6% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request. | |
| Modificada | Media (6.1) | 1.1% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.8% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request. | |
| Modificada | Media (5.3) | 1.4% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors. | |
| Modificada | Media (5.3) | 1.5% | — | IBM Bigfix Remote Control | 30/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network. | |
| Modificada | Alta (8.1) | 1.3% | — | IBM Bigfix Remote Control | 25/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a brute-force approach. | |
| Modificada | Media (4.3) | 1.0% | — | IBM Bigfix Remote Control | 25/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs. | |
| Modificada | Media (5.9) | 0.81% | — | IBM Bigfix Remote Control | 25/11/2016 | 17/6/2026 | IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data. | |
| Modificada | Media (6.4) | 0.38% | — | Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic IT Production SuiteSiemens Simatic NET PC Software+14 | 15/11/2016 | 17/6/2026 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7… | |
| Modificada | Media (6.1) | 1.6% | — | Siemens Sinema Remote Connect Server | 22/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.5) | 2.6% | — | Debian LinuxRemotesensing Libtiff | 13/4/2016 | 17/6/2026 | The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cvs-1.tif and libtiff-cvs-2.tif. | |
| Modificada | Crítica (9.8) | 51% | 💥 Exploit | Dameware Mini Remote Control | 17/3/2016 | 17/6/2026 | Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string. | |
| Modificada | Media (6.5) | 63% | 💥 PoC | Sophos Unified Threat Management SoftwareOracle LinuxOracle SolarisOpenbsd Openssh+2 | 14/1/2016 | 17/6/2026 | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key. | |
| Modificada | Media (4.3) | 2.0% | — | EMC Secure Remote Services | 28/12/2015 | 17/6/2026 | Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote authenticated users to read log files via a crafted parameter. | |
| Modificada | Alta (7.5) | 4.8% | — | Solarwinds Dameware Mini Remote Control | 17/11/2015 | 17/6/2026 | Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link. | |
| Modificada | Baja (3.7) | 0.34% | — | Apple MAC OS XApple Remote Desktop | 14/11/2015 | 16/6/2026 | The Remote Desktop full-screen feature in Apple OS X before 10.9 and Apple Remote Desktop before 3.7 sends dialog-box text to a connected remote host upon being woken from sleep, which allows physically proximate attackers to bypass intended access restrictions by entering a command in this box. | |
| Modificada | Alta (9.3) | 2.5% | — | EMC Secure Remote Services | 5/7/2015 | 17/6/2026 | EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value. | |
| Modificada | Media (5.8) | 0.67% | — | EMC Secure Remote Services | 5/7/2015 | 17/6/2026 | EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |