Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 1.0% | — | Juniper Paragon Active Assurance Control CenterFedoraproject Fedora | 22/4/2021 | 17/6/2026 | An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configuration including associated inventory details. If the issue occurs, the affected… | |
| Modificada | Media (5.5) | 0.32% | — | Gnome Control Center | 8/2/2021 | 17/6/2026 | A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password.… | |
| Modificada | Media (5.4) | 0.53% | — | Hivemq Broker Control Center | 26/8/2020 | 17/6/2026 | An issue was discovered in HiveMQ Broker Control Center 4.3.2. A crafted clientid parameter in an MQTT packet (sent to the Broker) is reflected in the client section of the management console. The attacker's JavaScript is loaded in a browser, which can lead to theft of the session and cookie of the administrator's… | |
| Modificada | Alta (7.2) | 2.6% | — | Killernetworking Killer Control Center | 20/3/2020 | 17/6/2026 | An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an arbitrary write primitive that can lead to code execution or escalation of privileges. | |
| Modificada | Baja (2.7) | 0.88% | — | Killernetworking Killer Control Center | 20/3/2020 | 17/6/2026 | An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an out-of-bounds read that can be used as part of a chain to escalate privileges (issue 2 of 2). | |
| Modificada | Baja (2.7) | 0.88% | — | Killernetworking Killer Control Center | 20/3/2020 | 17/6/2026 | An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an out-of-bounds read that can be used as part of a chain to escalate privileges (issue 1 of 2). | |
| Modificada | Baja (2.7) | 0.94% | — | Killernetworking Killer Control Center | 20/3/2020 | 17/6/2026 | An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120444 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an arbitrary read primitive that can be used as part of a chain to escalate privileges. | |
| Modificada | Alta (7.2) | 2.4% | — | Killernetworking Killer Control Center | 20/3/2020 | 17/6/2026 | An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to validate parameters, leading to a stack-based buffer overflow, which can lead to code execution or escalation of privileges. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel Control Center-i | 16/12/2019 | 17/6/2026 | Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 2.1% | — | Siemens Control Center Server | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) does not properly limit its capabilities to the specified purpose. In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network… | |
| Modificada | Crítica (9.8) | 7.0% | — | CA Workload Control Center | 11/4/2018 | 17/6/2026 | CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request. | |
| Modificada | Alta (7.1) | 1.6% | — | IBM Financial Transaction ManagerIBM Transformation Extender AdvancedIBM Control Center | 21/2/2018 | 17/6/2026 | IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker… | |
| Modificada | Media (5.1) | 0.26% | — | IBM Control CenterIBM Sterling Control Center | 8/7/2016 | 17/6/2026 | IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.7% | — | Avigilon Control Center | 23/6/2015 | 17/6/2026 | Directory traversal vulnerability in Avigilon Control Center (ACC) 4 before 4.12.0.54 and 5 before 5.4.2.22 allows remote attackers to read arbitrary files via a crafted help/ URL. | |
| Modificada | Baja (3.5) | 1.1% | — | IBM Sterling Control Center | 30/5/2014 | 17/6/2026 | Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | |
| Modificada | Baja (3.5) | 0.76% | — | IBM Sterling Control Center | 19/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters. | |
| Modificada | Media (6.3) | 0.94% | — | IBM Sterling Control Center | 19/6/2013 | 16/6/2026 | An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters. | |
| Modificada | Alta (7.8) | 2.3% | — | EMC Control Center | 10/12/2008 | 16/6/2026 | The SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center before 6.1 does not properly authenticate SST_SENDFILE requests, which allows remote attackers to read arbitrary files. | |
| Modificada | Alta (10) | 7.7% | — | EMC Control Center | 10/12/2008 | 16/6/2026 | Stack-based buffer overflow in SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center 5.2 SP5 and 6.0 allows remote attackers to execute arbitrary code via multiple SST_CTGTRANS requests. | |
| Modificada | Alta (7.5) | 2.6% | — | Arcserve BrightstorBroadcom Cleverpath PortalCleverpath Aion BPMCleverpath Portal+7 | 20/12/2006 | 16/6/2026 | Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are… | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Paul Schudar Tagmin Control Center | 29/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Media (5) | 59% | 💥 Exploit | Nortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+15 | 23/12/2004 | 16/6/2026 | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number… |