Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

136 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.43%—Mhuertos PhpldapadminAI11/7/202417/6/2026
A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38. Affected by this vulnerability is the function makeHttpRequest of the file htdocs/js/ajax_functions.js. The manipulation leads to http request smuggling. The attack can be launched remotely. This…
AplazadaMedia (6.1)0.25%—Virtosoftware Virto Kanban Board WEB PartAI25/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS.
ModificadaAlta (8.1)0.61%—Amazon Freertos-plus-tcp24/6/202417/6/2026
FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response with domain name length value greater than the actual domain name…
ModificadaMedia (5.3)0.47%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
ModificadaMedia (5.3)0.34%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.
ModificadaCrítica (9.8)0.61%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.
ModificadaAlta (7.8)0.24%—Amazon Freertos7/3/202417/6/2026
FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist that allows code injection and execution. These issues affect ARMv7-M MPU ports,…
ModificadaCrítica (9.8)1.3%—Microsoft Azure Rtos Threadx5/12/202317/6/2026
Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arbitrary read and write due to vulnerability in parameter checking mechanism in Azure RTOS ThreadX, which may lead to privilege escalation. The affected components include…
ModificadaCrítica (9.8)3.1%—Microsoft Azure Rtos Netx DUO5/12/202317/6/2026
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to icmp, tcp, snmp, dhcp, nat…
ModificadaCrítica (9.8)3.1%—Microsoft Azure Rtos Netx DUO5/12/202317/6/2026
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause an out-of-bounds write in Azure RTOS NETX Duo, that could lead to remote code execution. The affected components include process related to IGMP protocol in RTOS v6.2.1 and…
ModificadaCrítica (9.8)4.3%—Microsoft Azure Rtos Netx DUO5/12/202317/6/2026
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to snmp, smtp, ftp and dtls in…
ModificadaCrítica (9.8)3.9%—Microsoft Azure Rtos Netx DUO5/12/202317/6/2026
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to ftp and sntp in RTOS v6.2.1…
ModificadaAlta (7.8)0.28%—Amazon FreertosTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+221/11/202317/6/2026
Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution.
ModificadaAlta (7.8)0.76%—Microsoft Azure Rtos Guix Studio10/10/202317/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.33%—IllumosOmniosce OmniosOpenindianaJoyent Smartos+126/12/202217/6/2026
An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is…
ModificadaAlta (7.8)0.80%—Microsoft Azure Rtos Guix Studio9/11/202210/8/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.89%—Microsoft Azure Rtos Filex8/11/202217/6/2026
Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory contents. When a valid log file with…
ModificadaCrítica (9.8)2.1%—Microsoft Azure Rtos Usbx4/11/202217/6/2026
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker…
ModificadaCrítica (9.8)1.1%—ARM Cmsis-rtos3/5/202217/6/2026
ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.
ModificadaAlta (7.8)0.34%—Amazon Freertos17/11/202117/6/2026
FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ability to execute injected code to achieve further privilege…
ModificadaMedia (4.6)1.1%—Microsoft Azure Rtos10/11/202119/8/2026
Azure RTOS Information Disclosure Vulnerability
ModificadaAlta (7.5)0.99%—Hilscher RCX RtosPepperl-fuchs Ice1-16di-g60l-v1d FirmwarePepperl-fuchs Ice1-16dio-g60l-c1-v1d FirmwarePepperl-fuchs Ice1-16dio-g60l-v1d Firmware+513/5/202117/6/2026
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.
ModificadaCrítica (9.8)1.3%—Amazon Freertos3/5/202117/6/2026
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.
ModificadaCrítica (9.8)1.4%—Amazon Freertos22/4/202117/6/2026
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.
ModificadaCrítica (9.8)1.4%—Amazon Freertos22/4/202117/6/2026
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.
Orbitaley — Vulnerabilidades