Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.61% | — | Pexip Infinity | 25/12/2023 | 17/6/2026 | Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort. | |
| Modificada | Alta (8.8) | 0.21% | — | ABB Infinity DC Power PlantABB Ne843 S | 24/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode… | |
| Modificada | Crítica (9.8) | 0.91% | — | Pega Infinity | 25/7/2022 | 17/6/2026 | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. | |
| Modificada | Crítica (9.8) | 12% | — | Pega Infinity | 19/7/2022 | 17/6/2026 | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its… | |
| Modificada | Alta (7.5) | 1.0% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP. | |
| Modificada | Alta (8.2) | 1.1% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. | |
| Modificada | Alta (7.5) | 1.1% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol. | |
| Modificada | Media (5.9) | 0.97% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. | |
| Modificada | Alta (8.2) | 1.1% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a software abort via a gateway call into Teams. | |
| Modificada | Alta (7.5) | 1.2% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity before 27.3 allows remote attackers to force a software abort via HTTP. | |
| Modificada | Media (5.3) | 0.66% | — | Pexip Infinity | 17/7/2022 | 17/6/2026 | Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN. | |
| Modificada | Alta (8.8) | 0.66% | — | Cybelesoft Thinfinity VNC | 20/5/2022 | 17/6/2026 | Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE. | |
| Modificada | Alta (7.5) | 1.3% | — | Pexip Infinity | 18/2/2022 | 17/6/2026 | Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote attacker can use excessive resources, temporarily causing denial of service. | |
| Modificada | Crítica (9.8) | 0.68% | — | Pexip Infinity Connect | 18/2/2022 | 17/6/2026 | Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked. | |
| Modificada | Crítica (9.8) | 0.54% | — | Pexip Infinity Connect | 18/2/2022 | 17/6/2026 | Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute. |