Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.63%—Hikvision Localservicecomponents23/11/202317/6/2026
An attacker could exploit a vulnerability by sending crafted messages to computers installed with this plug-in to modify plug-in parameters, which could cause affected computers to download malicious files.
ModificadaCrítica (9.8)0.97%—Hikvision Localservicecomponents23/11/202317/6/2026
There is a buffer overflow vulnerability in a web browser plug-in could allow an attacker to exploit the vulnerability by sending crafted messages to computers installed with this plug-in, which could lead to arbitrary code execution or cause process exception of the plug-in.
ModificadaCrítica (9.8)0.46%—Componentspace Saml24/3/20239/7/2026
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion between entities within a trust…
AnalizadaCrítica (9.8)1.4%—Zetacomponents Mvctools22/2/202317/6/2026
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.
ModificadaMedia (5.4)0.45%—Linuxfoundation Backstage Catalog-modelLinuxfoundation Backstage Core-componentsLinuxfoundation Backstage Plugin-catalog-backend14/2/202317/6/2026
Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior to 0.12.4, and `@backstage/plugin-catalog-backend` prior to 1.7.2 are affected by a cross-site scripting vulnerability. This vulnerability allows a malicious actor with…
ModificadaAlta (8.1)0.70%—Oracle Peoplesoft Enterprise Common Components18/10/202217/6/2026
Vulnerability in the PeopleSoft Enterprise Common Components product of Oracle PeopleSoft (component: Approval Framework). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise Common Components.…
ModificadaMedia (5.4)0.70%—Adobe WEB Content Management Core Components10/8/202217/6/2026
Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.…
ModificadaMedia (5.5)2.2%—Rockwellautomation Connected Components WorkbenchRockwellautomation IsagrafRockwellautomation Safety Instrumented Systems Workstation1/4/202217/6/2026
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server, leading to a loss of confidentiality.
ModificadaAlta (8.6)3.0%—Rockwellautomation Connected Components Workbench23/3/202217/6/2026
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in remote code execution. This…
ModificadaAlta (8.2)0.78%—Rockwellautomation Connected Components Workbench23/3/202217/6/2026
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip Slip. A local, authenticated attacker can create a malicious .ccwarc archive file that, when…
ModificadaAlta (8.6)2.9%—Rockwellautomation Connected Components Workbench23/3/202217/6/2026
The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an…
ModificadaMedia (6.1)0.69%—Amazon Awsui/components-react24/2/202217/6/2026
@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to…
ModificadaMedia (5.5)1.2%—International Components FOR UnicodeDebian Linux20/9/202117/6/2026
International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.
ModificadaMedia (6.5)0.90%—Oracle Peoplesoft Enterprise HCM Shared Components21/7/202117/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared…
ModificadaAlta (8.2)1.5%—Kuka Visual Components Network License Server6/11/202017/6/2026
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making processes. Visual Components software requires a special license which can beobtained from a network license server. The network license server binds to all interfaces…
ModificadaAlta (7.5)1.4%—Kuka Visual Components Network License Server6/11/202017/6/2026
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making processes. Visual Components software requires a special license which can beobtained from a network license server. The network license server binds to all interfaces…
ModificadaAlta (8.8)2.7%—Icu-project International Components FOR UnicodeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+712/3/202017/6/2026
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
ModificadaMedia (6.1)0.80%—Tennisconnect Components28/1/202017/6/2026
Cross-site scripting (XSS) vulnerability in TennisConnect COMPONENTS 9.927 allows remote attackers to inject arbitrary web script or HTML via the pid parameter to index.cfm.
ModificadaAlta (7.5)1.6%—Sitebuilder Dynamic Components Project Sitebuilder Dynamic Components10/9/201917/6/2026
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
ModificadaMedia (6.1)1.3%—Components FOR WP Bakery Page Builder Project Components FOR WP Bakery Page Builder29/8/201917/6/2026
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
ModificadaMedia (4.2)1.2%—Oracle Siebel Core - Common Components23/7/201917/6/2026
Vulnerability in the Siebel Core - Common Components component of Oracle Siebel CRM (subcomponent: Email). Supported versions that are affected are 19.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Core - Common Components. Successful…
ModificadaMedia (6.6)1.2%—Omron Common ComponentsOmron Cx-programmer10/4/201917/6/2026
When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
ModificadaCrítica (9.8)2.8%—Icu-project International Components FOR Unicode4/11/201817/6/2026
International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp.
ModificadaMedia (6.5)2.2%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+228/8/201817/6/2026
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)2.5%—Google ChromeIcu-project International Components FOR UnicodeDebian LinuxCanonical Ubuntu Linux+328/8/201817/6/2026
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.