Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 40% | 💥 Exploit | Esafenet Electronic Document Security Management System | 8/3/2019 | 17/6/2026 | ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request. | |
| Modificada | Alta (7.5) | 3.0% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+14 | 19/2/2019 | 17/6/2026 | Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0. | |
| Modificada | Alta (7.5) | 2.6% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+11 | 19/2/2019 | 17/6/2026 | Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0. | |
| Modificada | Crítica (9.8) | 5.4% | — | Yokogawa B/M 9000 VPYokogawa Centum VPYokogawa PRMYokogawa Prosafe-rs | 13/2/2019 | 17/6/2026 | License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License… | |
| Modificada | Alta (7.5) | 2.7% | — | Trendmicro DR. Safety | 5/2/2019 | 17/6/2026 | A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations. | |
| Modificada | Media (4.9) | 0.72% | — | Oracle Argus Safety | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Argus Safety component of Oracle Health Sciences Applications (subcomponent: Login). Supported versions that are affected are 8.1 and 8.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Safety. While the… | |
| Modificada | Media (6.1) | 1.3% | — | Oracle Argus Safety | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Argus Safety component of Oracle Health Sciences Applications (subcomponent: Console). Supported versions that are affected are 8.1 and 8.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Argus Safety. Successful attacks… | |
| Modificada | Media (6.5) | 1.5% | — | Oracle Argus Safety | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Argus Safety component of Oracle Health Sciences Applications (subcomponent: Console). Supported versions that are affected are 8.1 and 8.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Safety. Successful attacks of… | |
| Modificada | Alta (7.5) | 3.3% | — | Yokogawa Centum CS 3000 FirmwareYokogawa Centum CS 3000 Entry ClassYokogawa Centum VP FirmwareYokogawa Centum VP Entry Class+5 | 9/1/2019 | 17/6/2026 | Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 -… | |
| Modificada | Crítica (9.8) | 4.0% | — | Yokogawa Idefine FOR Prosafe-rs FirmwareYokogawa Stardom Versatile Data Server FirmwareYokogawa Stardom Fcn/fcj Simulator FirmwareYokogawa Astplanner+1 | 9/1/2019 | 17/6/2026 | Buffer overflow in the license management function of YOKOGAWA products (iDefine for ProSafe-RS R1.16.3 and earlier, STARDOM VDS R7.50 and earlier, STARDOM FCN/FCJ Simulator R4.20 and earlier, ASTPLANNER R15.01 and earlier, TriFellows V5.04 and earlier) allows remote attackers to stop the license management function… | |
| Modificada | Alta (8.8) | 1.0% | — | Safe FME Server | 23/12/2018 | 17/6/2026 | Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account. The passwords to the three accounts are the same as the usernames, which are guest, user, and author. Logging in with these accounts will grant any user the default privilege roles… | |
| Modificada | Media (6.5) | 0.95% | — | Trendmicro DR. Safety | 21/12/2018 | 17/6/2026 | An Address Bar Spoofing vulnerability in Trend Micro Dr. Safety for Android (Consumer) versions 3.0.1324 and below could allow an attacker to potentially trick a victim into visiting a malicious URL using address bar spoofing on the Private Browser of the app on vulnerable installations. | |
| Modificada | Alta (7.5) | 2.6% | — | Dell BsafeOracle Application Testing SuiteOracle Communications AnalyticsOracle Communications IP Service Activator+8 | 16/11/2018 | 17/6/2026 | RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Service (DoS) on TLS clients during the handshake when a very large prime value is sent to the TLS… | |
| Modificada | Alta (7.8) | 0.33% | — | Ftsafe Securecore | 15/11/2018 | 17/6/2026 | SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Windows PC. | |
| Modificada | Media (6.1) | 0.72% | — | Bullguard Safe Browsing | 15/9/2018 | 17/6/2026 | BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search results. | |
| Modificada | Crítica (9.8) | 4.0% | — | Dell BsafeDell Bsafe Crypto-cOracle Application Testing SuiteOracle Communications Analytics+9 | 14/9/2018 | 17/6/2026 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result… | |
| Modificada | Alta (8.8) | 2.4% | — | F5 Websafe Alert Server | 13/9/2018 | 17/6/2026 | On F5 WebSafe Alert Server 1.0.0-4.2.6, a malicious, authenticated user can execute code on the alert server by using a maliciously crafted payload. | |
| Modificada | Media (5.9) | 1.7% | — | Dell Bsafe Crypto-jDell RSA Bsafe Ssl-j | 11/9/2018 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during PKCS #1 unpadding operations, also known as a Bleichenbacher attack. A remote attacker may be able to recover a RSA key. | |
| Modificada | Media (5.9) | 1.3% | — | Dell Bsafe Ssl-j | 11/9/2018 | 17/6/2026 | RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key. | |
| Modificada | Media (4.6) | 0.42% | — | Dell Bsafe Ssl-j | 11/9/2018 | 17/6/2026 | RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physical access to the system to recover sensitive key material. | |
| Modificada | Media (5.9) | 1.7% | — | Dell BsafeOracle Application Testing SuiteOracle Communications AnalyticsOracle Communications IP Service Activator+8 | 31/8/2018 | 17/6/2026 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key. | |
| Modificada | Media (6.5) | 1.9% | — | Dell BsafeDell Bsafe Crypto-cOracle Application Testing SuiteOracle Communications Analytics+9 | 31/8/2018 | 17/6/2026 | RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would… | |
| Modificada | Media (5.5) | 0.43% | — | Dell BsafeOracle Application Testing SuiteOracle Communications AnalyticsOracle Communications IP Service Activator+8 | 31/8/2018 | 17/6/2026 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local… | |
| Modificada | Alta (7.5) | 3.2% | — | Dell BsafeOracle Application Testing SuiteOracle Communications AnalyticsOracle Communications IP Service Activator+8 | 31/8/2018 | 17/6/2026 | RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service. | |
| Modificada | Alta (7.5) | 0.99% | — | Psafe Dfndr Security | 15/8/2018 | 17/6/2026 | DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |