Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

933 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.74%—Phpjabbers Fundraising Script5/11/202117/6/2026
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionLoadCss function.
ModificadaMedia (6.7)0.13%—ABB Update Manager28/10/202117/6/2026
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.
ModificadaCrítica (9.4)0.66%—ABB MybuildingsMybusch-jaeger27/9/202117/6/2026
The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/his my.busch-jaeger.de or mybuildings.abb.com profile. A successful attacker can observe and control a ControlTouch remotely under very…
ModificadaMedia (5.5)0.26%—ABB System Access Point 2.0 FirmwareABB System Access Point 127v FirmwareABB Wl-system Access Point 127v FirmwareABB Wl-system Access Point Firmware+123/9/202117/6/2026
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.
ModificadaAlta (7.8)0.13%—Hitachiabb-powergrids Sdm600 Firmware8/9/202117/6/2026
Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6 (Build Nr. 1.2.14002.257).
ModificadaCrítica (9.8)0.54%—ABB Base Software8/9/202117/6/2026
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .
ModificadaMedia (4.8)1.4%—Vmware Rabbitmq28/6/202117/6/2026
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript…
ModificadaMedia (5.4)1.4%—Vmware Rabbitmq28/6/202117/6/2026
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially allowing for JavaScript code execution in the context of the…
ModificadaMedia (6.5)0.79%—Cisco Jabber16/6/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (6.5)0.80%—Cisco Jabber16/6/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (5.4)0.51%—Hitachiabb-powergrids Ellipse Asset Performance Management14/6/202117/6/2026
Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or integrated application to inject malicious data into the application that can then be executed in a victim’s browser. This issue affects: Hitachi ABB Power Grids Ellipse APM 5.3 version 5.3.0.1 and…
ModificadaAlta (7.5)1.4%—Vmware RabbitmqDebian Linux8/6/202117/6/2026
RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.
ModificadaAlta (7.8)0.61%—Broadcom Rabbitmq Server18/5/202117/6/2026
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
ModificadaMedia (6.5)0.81%—Jenkins Jabber (xmpp) Notifier AND Control30/3/202117/6/2026
Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (6.5)0.94%—Cisco Jabber24/3/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of…
ModificadaMedia (6.5)0.96%—Cisco Jabber24/3/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of…
ModificadaCrítica (9.9)1.4%—Cisco Jabber24/3/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of…
ModificadaMedia (5.6)1.3%—Cisco Jabber24/3/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of…
ModificadaAlta (7.2)1.0%—Cisco Jabber24/3/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of…
ModificadaCrítica (9.8)2.8%—Rabbitmq JMS Client12/3/202117/6/2026
JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.
ModificadaAlta (8.8)2.2%—Zabbix3/3/202117/6/2026
In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the init() method. An attacker doesn't have…
ModificadaAlta (7.5)2.5%—ABB Pm554 FirmwareABB Pm556 FirmwareABB Pm564 FirmwareABB Pm566 Firmware+226/2/202117/6/2026
The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show an error state and refuse connections to…
ModificadaAlta (8.6)1.6%—ABB Ac500 CPU Firmware9/2/202117/6/2026
An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB…
ModificadaCrítica (9.9)2.3%—Cisco Jabber7/1/202117/6/2026
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see…
ModificadaCrítica (9.8)1.5%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network…