Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.70% | — | Deltacontrols Entelitouch Firmware | 2/6/2022 | 17/6/2026 | Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive information in cleartext. This vulnerability allows attackers to intercept HTTP Cookie authentication credentials via a man-in-the-middle attack. | |
| Modificada | Media (6.1) | 0.76% | — | Deltacontrols Entelitouch Firmware | 2/6/2022 | 17/6/2026 | Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via the Username parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Alta (8.8) | 1.9% | — | Anaconda3 | 13/5/2022 | 17/6/2026 | Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed. | |
| Modificada | Media (5.9) | 0.74% | — | Sealevel Seaconnect 370w Firmware | 14/4/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.33% | — | Anaconda3Miniconda3 | 17/3/2022 | 17/6/2026 | Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example, local users can gain privileges by placing a Trojan horse file into that… | |
| Modificada | Media (5.9) | 0.70% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to an out-of-bounds write. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 0.89% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [3] the json_object_get_string to populate the p_name global variable. The p_name is only 0x80 bytes long, and the total MQTT… | |
| Modificada | Alta (8.1) | 0.89% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [4] the json_object_get_string to populate the p_payload global variable. The p_payload is only 0x100 bytes long, and the total… | |
| Modificada | Alta (8.3) | 0.95% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Crítica (9.3) | 1.0% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.4) | 0.71% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Media (5.9) | 0.49% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 2.0% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-in-the-middle attack in order to trigger this vulnerability. | |
| Modificada | Crítica (10) | 2.6% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (10) | 2.6% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 0.84% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality. | |
| Modificada | Crítica (9.8) | 3.0% | — | Anaconda Dask | 26/10/2021 | 17/6/2026 | An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client (which defaults to using LocalCluster) would mistakenly configure their respective Dask workers to listen on external interfaces… | |
| Modificada | Media (5.4) | 0.51% | — | Alkacon Opencms | 19/10/2021 | 17/6/2026 | In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the Sitemap functionality. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field. | |
| Modificada | Media (6.5) | 1.3% | — | Alkacon Opencms | 8/10/2021 | 17/6/2026 | An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document. | |
| Modificada | Alta (7.5) | 1.2% | — | Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+8 | 4/10/2021 | 17/6/2026 | Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server… | |
| Modificada | Media (5.5) | 0.23% | — | Flexera Flexnet Inventory Agent AND Beacon | 21/9/2021 | 17/6/2026 | An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNet inventory agent and inventory beacon versions 2020 R2.5 and prior. | |
| Modificada | Alta (8.8) | 2.0% | — | Katacontainers Kata Containers | 7/12/2020 | 17/6/2026 | An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes. | |
| Modificada | Alta (7.1) | 0.37% | — | Katacontainers Kata-containers | 17/11/2020 | 17/6/2026 | An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container… | |
| Modificada | Alta (8.8) | 0.47% | — | Katacontainers RuntimeFedoraproject Fedora | 10/6/2020 | 17/6/2026 | A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11… | |
| Modificada | Media (6.3) | 1.1% | 💥 PoC | Katacontainers Runtime | 10/6/2020 | 17/6/2026 | Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than… |