Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.24%—PTC Kepware KepserverexPTC Thingworx Kepware ServerPTC Thingworx Industrial Connectivity10/1/202417/6/2026
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.
ModificadaAlta (7.3)0.20%—PTC Kepware KepserverexPTC Thingworx Kepware ServerPTC Thingworx Industrial Connectivity10/1/202417/6/2026
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to…
ModificadaCrítica (9.8)0.96%—Phz76 Rtspserver17/12/202317/6/2026
A vulnerability classified as critical was found in PHZ76 RtspServer 1.0.0. This vulnerability affects the function ParseRequestLine of the file RtspMesaage.cpp. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.…
ModificadaAlta (7.5)0.44%—GE Industrial Gateway ServerPTC KeepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+430/11/202317/6/2026
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
ModificadaCrítica (9.1)0.96%—GE Industrial Gateway ServerPTC KeepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+430/11/202317/6/2026
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
ModificadaCrítica (9.8)2.0%—Fit2cloud Jumpserver28/11/20239/7/2026
Insecure Permissions vulnerability in JumpServer GPLv3 v.3.8.0 allows a remote attacker to execute arbitrary code via bypassing the command filtering function. NOTE: this is disputed because command filtering is not intended to restrict what code can be run by authorized users who are allowed to execute files.
ModificadaMedia (5.3)0.32%—Fit2cloud Jumpserver31/10/202317/6/2026
JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Prior to version 3.8.0, the default email for initial user admin is `admin[@]mycompany[.]com`, and users reset their passwords by sending an email. Currently, the domain `mycompany.com` has not been…
ModificadaMedia (5.3)0.70%—Fit2cloud Jumpserver25/10/202317/6/2026
jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A flaw in the Core API allows attackers to bypass password brute-force protections by spoofing arbitrary IP addresses. By exploiting this vulnerability, attackers can…
ModificadaCrítica (9.9)2.1%—Fit2cloud Jumpserver27/9/202317/6/2026
JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leading to remote code execution. This vulnerability may further be leveraged to gain root privileges on the system. Through the WEB CLI interface provided by the koko…
ModificadaCrítica (9.8)0.68%—Fit2cloud Jumpserver27/9/202317/6/2026
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a disclosed public key to attempt brute-force authentication against the SSH service…
AnalizadaCrítica (9.1)0.81%—Fit2cloud Jumpserver27/9/202317/6/2026
JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a password or the corresponding SSH private key. An SSH public key should be considered public knowledge and should not used as an authentication…
AnalizadaAlta (7.4)0.60%—Fit2cloud Jumpserver27/9/202317/6/2026
JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absence of rate limiting. JumpServer provides a feature allowing users to reset forgotten passwords. Affected users are sent a 6-digit verification code, ranging from 000000 to…
ModificadaAlta (8.2)6.3%💥 PoCFit2cloud Jumpserver27/9/202317/6/2026
JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly generated verification codes to be replayed, which could lead to password resets. If MFA is enabled users are not affect. Users not using local authentication are also…
ModificadaAlta (8.8)2.2%💥 PoCFit2cloud Jumpserver27/9/202317/6/2026
JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Template' menu and create a playbook named 'test'. Get the playbook id from the detail page, like 'e0adabef-c38f-492d-bd92-832bacc3df5f'. An attacker can exploit the…
ModificadaMedia (5.3)63%💥 ExploitFit2cloud Jumpserver15/9/202317/6/2026
JumpServer is an open source bastion host and a professional operation and maintenance security audit system. Starting in version 3.0.0 and prior to versions 3.5.5 and 3.6.4, session replays can download without authentication. Session replays stored in S3, OSS, or other cloud storage are not affected. The api…
ModificadaAlta (8.8)0.56%—Wftpserver Wing FTP Server12/9/202317/6/2026
Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
ModificadaAlta (7.5)0.53%—Wftpserver Wing FTP Server12/9/202317/6/2026
Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0.
ModificadaAlta (8.8)0.51%—Wftpserver Wing FTP Server12/9/202317/6/2026
Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
ModificadaMedia (5.4)0.29%—Wftpserver Wing FTP Server12/9/202317/6/2026
Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0.
ModificadaMedia (6.5)0.47%—Matrix-appservice-bridge4/8/202317/6/2026
matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user's MXID in an OpenID exchange, allowing a bad actor to impersonate users when using the provisioning API. The library does not check that the…
ModificadaAlta (7.5)0.76%—Kepware Kepserverex31/7/202317/6/2026
PTC’s KEPServerEX Versions 6.0 to 6.14.263 are vulnerable to being made to read a recursively defined object that leads to uncontrolled resource consumption. KEPServerEX uses OPC UA, a protocol which defines various object types that can be nested to create complex arrays. It does not implement a check to see if such…
ModificadaAlta (7.5)0.78%—Wpserveur WPS Hide Login7/6/202317/6/2026
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
ModificadaCrítica (9.1)3.4%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+429/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation…
ModificadaCrítica (9.8)3.4%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+429/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation…
ModificadaAlta (8)0.25%—Propumpservice Osprey Pump Controller Firmware28/3/202317/6/2026
Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
Orbitaley — Vulnerabilidades