Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.2% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy Manager+6 | 25/7/2018 | 17/6/2026 | A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual server is configured with a HTML or a Rewrite profile. TMM may restart while processing some specially prepared HTML content from the back end. | |
| Modificada | Alta (7.5) | 1.8% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+5 | 25/7/2018 | 17/6/2026 | F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerable to "HPACK Bomb". | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x802022E0. By crafting an input buffer we can control the execution path to the point where the constant 0x12 will be written to a user-controlled… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x8020601C. By crafting an input buffer we can control the execution path to the point where a global variable will be written to a user controlled… | |
| Modificada | Alta (7.8) | 0.54% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80202014. By crafting an input buffer we can control the execution path to the point where the constant 0xFFFFFFF will be written to a user-controlled… | |
| Modificada | Alta (7.8) | 0.60% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via multiple IOCTLs, e.g., 0x8810200B, 0x8810200F, 0x8810201B, 0x8810201F, 0x8810202B, 0x8810202F, 0x8810203F, 0x8810204B, 0x88102003, 0x88102007, 0x88102013,… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206024. By crafting an input buffer we can control the execution path to the point where a global variable will be written to a user controlled… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80202298. By crafting an input buffer we can control the execution path to the point where the nt!memset function is called to zero out contents of a… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206040. By crafting an input buffer we can control the execution path to the point where the constant DWORD 0 will be written to a user-controlled… | |
| Modificada | Alta (7.8) | 0.27% | — | Safensoft Enterprise SuiteSafensoft SyswatchSafensoft Tpsecure | 29/6/2018 | 17/6/2026 | Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.2 allows the local attacker to restore the SysWatch password from the settings database and modify program… | |
| Modificada | Alta (7.8) | 0.19% | — | Safensoft Enterprise SuiteSafensoft SyswatchSafensoft Tpsecure | 29/6/2018 | 17/6/2026 | Improper check of unusual conditions when launching msiexec.exe in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.9 allows the local attacker to bypass a code-signing protection mechanism and… | |
| Modificada | Alta (8.1) | 0.51% | — | Safensoft Softcontrol Enterprise SuiteSafensoft Softcontrol SyswatchSafensoft Softcontrol Tpsecure | 29/6/2018 | 17/6/2026 | Download of code with improper integrity check in snsupd.exe and upd.exe in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.12 allows the remote attacker to execute unauthorized code by substituting a forged update server. | |
| Modificada | Alta (7.5) | 2.5% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+9 | 27/6/2018 | 17/6/2026 | On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled can force the Traffic Management Microkernel (tmm) to leak memory. As a result, system memory usage increases over time, which… | |
| Modificada | Alta (7.1) | 0.27% | — | Safensoft Softcontrol Enterprise SuiteSafensoft Softcontrol SyswatchSafensoft Softcontrol Tpsecure | 12/6/2018 | 17/6/2026 | Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, SoftControl/SafenSoft Enterprise Suite before version 4.4.1 allows local users to cause a denial of service (BSOD) or modify kernel-mode memory via loading of… | |
| Modificada | Crítica (10) | 3.5% | 💥 PoC | Safe-eval Project Safe-eval | 7/6/2018 | 17/6/2026 | The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox. | |
| Modificada | Media (5.9) | 1.5% | — | F5 Big-ip Application Acceleration ManagerF5 Big-ip Local Traffic ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 1/6/2018 | 17/6/2026 | On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute-value pairs, TMM may crash. | |
| Modificada | Media (6.1) | 0.92% | — | F5 Big-ip Application Acceleration ManagerF5 Big-ip Local Traffic ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 1/6/2018 | 17/6/2026 | On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS. | |
| Modificada | Alta (7.5) | 1.8% | — | F5 Big-ip Application Acceleration ManagerF5 Big-ip Local Traffic ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 1/6/2018 | 17/6/2026 | On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leading to a disruption of service. This issue is only exposed on the data plane when Proxy SSL configuration is enabled. The control plane is not impacted by this issue. | |
| Modificada | Media (6.6) | 0.23% | — | Simplisafe U9k-kp1000 Firmware | 24/5/2018 | 17/6/2026 | SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN. | |
| Modificada | Media (4.6) | 0.31% | — | Simplisafe U9k-bs1000 Firmware | 24/5/2018 | 17/6/2026 | In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker does not cause a notification. | |
| Modificada | Media (4.6) | 0.31% | — | Simplisafe U9k-bs1000 Firmware | 24/5/2018 | 17/6/2026 | In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physically proximate attacker removes the battery and external power. | |
| Modificada | Media (4.3) | 0.23% | — | Simplisafe U9k-es1000 FirmwareSimplisafe U9k-kr1 FirmwareSimplisafe U9k-ms1000 FirmwareSimplisafe U9k-wt1000 Firmware | 24/5/2018 | 17/6/2026 | SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur. | |
| Modificada | Media (4.4) | 1.0% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 2/5/2018 | 17/6/2026 | On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthorized access to file system resources. | |
| Modificada | Media (4.9) | 1.0% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 2/5/2018 | 17/6/2026 | On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.3, or 11.2.1-11.6.3.1, administrative users by way of undisclosed methods can exploit the ssldump utility to write to arbitrary file paths. For users who do not have Advanced Shell access (for example, any user when licensed for Appliance Mode), this allows more permissive… | |
| Modificada | Media (5.4) | 0.41% | — | F5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 2/5/2018 | 17/6/2026 | On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest can cause a disruption of service on adjacent VCMP guests running on the same host. Exploiting this vulnerability causes the vCMPd process on the adjacent VCMP guest to restart and produce a core file. This issue is only… |