Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Bomgar Remote Support | 25/5/2015 | 17/6/2026 | Bomgar Remote Support before 15.1.1 allows remote attackers to execute arbitrary PHP code via crafted serialized data to unspecified PHP scripts. | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | Sonicwall Remote Access Firmware | 1/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to… | |
| Modificada | Alta (7.5) | 3.7% | — | EMC Secure Remote Services | 12/3/2015 | 17/6/2026 | The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | EMC Secure Remote Services | 12/3/2015 | 17/6/2026 | SQL injection vulnerability in the Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.8% | — | Cybozu Remote Service Manager | 1/2/2015 | 17/6/2026 | Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1983. | |
| Modificada | Alta (10) | 6.0% | — | Emerson DL 8000 Remote Terminal Unit FirmwareEmerson DL 8000 Remote Terminal UnitEmerson ROC 800l Remote Terminal Unit FirmwareEmerson ROC 800l Remote Terminal Unit+2 | 8/12/2014 | 16/6/2026 | Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a TCP replay attack. | |
| Modificada | Media (5.4) | 0.27% | — | Utorrent Remote | 9/9/2014 | 17/6/2026 | The uTorrent Remote (aka com.utorrent.web) application 1.0.20110929 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Islonline ISL Light Remote Desktop | 9/9/2014 | 17/6/2026 | The ISL Light Remote Desktop (aka com.islonline.isllight.mobile.android) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Entertailion Able Remote | 9/9/2014 | 17/6/2026 | The Able Remote (aka com.entertailion.android.remote) application 2.3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Deskroll Remote Desktop | 9/9/2014 | 17/6/2026 | The DeskRoll Remote Desktop (aka com.deskroll.client1) application 0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Nagios Remote Plugin ExecutorOpensuse | 7/5/2014 | 17/6/2026 | Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows… | |
| Modificada | Media (6.8) | 1.7% | — | Cybozu Remote Service Manager | 19/4/2014 | 17/6/2026 | Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.3% | — | Cybozu Remote Service Manager | 19/4/2014 | 17/6/2026 | Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (CPU consumption) via unknown vectors. | |
| Modificada | Media (4.9) | 0.34% | — | Remote-rac RAC Server | 18/4/2014 | 17/6/2026 | PCNetSoftware RAC Server 4.0.4 and 4.0.5 allows local users to cause a denial of service (disabled keyboard or crash) via a large input buffer to unspecified IOCTL requests in RACDriver.sys, which triggers a buffer over-read. | |
| Modificada | Alta (9.3) | 6.0% | — | Solarwinds Dameware Remote Support | 20/3/2014 | 16/6/2026 | Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372, 9.0.1.247, and earlier allows user-assisted attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Apple Remote Desktop | 24/10/2013 | 16/6/2026 | Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message, which allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended… | |
| Modificada | Alta (7.5) | 11% | — | Apple Remote DesktopApple MAC OS X | 24/10/2013 | 16/6/2026 | Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers in a VNC username. | |
| Modificada | Alta (9) | 2.6% | — | Enea OSEEmerson DL 8000 Remote Terminal UnitEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the… | |
| Modificada | Alta (10) | 3.3% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson DL 8000 Remote Terminal UnitEmerson ROC 800 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device… | |
| Modificada | Alta (10) | 4.9% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal UnitEmerson DL 8000 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service. | |
| Modificada | Alta (10) | 5.0% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal UnitEmerson DL 8000 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.5) | 0.96% | — | IBM Tivoli Remote Control | 29/7/2013 | 16/6/2026 | SQL injection vulnerability in the server component in IBM Tivoli Remote Control 5.1.2 before 5.1.2-TIV-TRC512-IF0015 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (9) | 2.5% | — | Wave Embassy Remote Administration ServerWave Embassy Remote Administration Server Help Desk | 15/7/2013 | 16/6/2026 | SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field), leading to execution of operating-system commands. | |
| Modificada | Alta (7.5) | 1.3% | — | Wave Embassy Remote Administration ServerWave Embassy Remote Administration Server Help Desk | 15/7/2013 | 16/6/2026 | SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote attackers to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field). | |
| Modificada | Alta (7.5) | 66% | 💥 Exploit | OpensuseNagios Remote Plug IN Executor | 9/7/2013 | 16/6/2026 | Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash. |