Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.20% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Media (5.5) | 0.23% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.23% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.20% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Media (5.5) | 0.21% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS). | |
| Modificada | Media (5.5) | 0.20% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Alta (7.8) | 0.19% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Axiros Axess Auto Configuration ServerAI | 24/6/2024 | 17/6/2026 | Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution. | |
| Aplazada | Crítica (9.4) | 0.48% | — | Baxter Welch Allyn Configuration ToolAI | 31/5/2024 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior. | |
| Aplazada | Alta (8.2) | 0.26% | — | Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+15 | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software… | |
| Aplazada | Alta (7.4) | 0.23% | — | Opentext Zenworks Configuration ManagementAI | 27/3/2024 | 17/6/2026 | Incorrect Authorization vulnerability in OpenText™ ZENworks Configuration Management (ZCM) allows Unauthorized Use of Device Resources.This issue affects ZENworks Configuration Management (ZCM) versions: 2020 update 3, 23.3, and 23.4. | |
| Analizada | Media (5.4) | 1.7% | — | Apache Commons ConfigurationFedoraproject Fedora | 21/3/2024 | 17/6/2026 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | |
| Analizada | Alta (7.3) | 2.1% | — | Apache Commons ConfigurationFedoraproject FedoraNetapp Ontap ToolsNetapp Snapcenter | 21/3/2024 | 17/6/2026 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. | |
| Modificada | Alta (8.1) | 0.55% | — | Tencent Blueking Configuration Management Database | 26/2/2024 | 9/7/2026 | Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request. | |
| Modificada | Crítica (9.8) | 1.0% | — | Yealink Configuration Encryption Tool | 23/2/2024 | 17/6/2026 | An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations. | |
| Analizada | Alta (7.5) | 0.44% | — | Yealink Configuration Encryption Tool | 20/2/2024 | 17/6/2026 | Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary. | |
| Analizada | Media (6.7) | 0.19% | — | Intel Qsfp+ Configuration Utility | 14/2/2024 | 17/6/2026 | Uncontrolled search path in Intel(R) QSFP+ Configuration Utility software, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Binary Configuration Tool | 14/2/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Binary Configuration Tool software before version 3.4.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 0.25% | — | Hidglobal Omnikey Secure Elements Reader Configuration Cards FirmwareHidglobal Iclass SE Reader Configuration Cards Firmware | 7/2/2024 | 17/6/2026 | Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys. | |
| Modificada | Alta (8.6) | 47% | 💥 Exploit | Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+3 | 8/1/2024 | 17/6/2026 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. | |
| Modificada | Media (5.9) | 0.56% | — | Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+10 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Alta (7.8) | 0.18% | — | Intel Server Configuration Utility | 14/11/2023 | 17/6/2026 | Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Server Configuration Utility | 14/11/2023 | 17/6/2026 | Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 2.1% | — | Solarwinds Network Configuration Manager | 9/11/2023 | 17/6/2026 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227 |