Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.43% | — | Mhuertos PhpldapadminAI | 11/7/2024 | 17/6/2026 | A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38. Affected by this vulnerability is the function makeHttpRequest of the file htdocs/js/ajax_functions.js. The manipulation leads to http request smuggling. The attack can be launched remotely. This… | |
| Aplazada | Media (6.1) | 0.25% | — | Virtosoftware Virto Kanban Board WEB PartAI | 25/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS. | |
| Modificada | Alta (8.1) | 0.61% | — | Amazon Freertos-plus-tcp | 24/6/2024 | 17/6/2026 | FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response with domain name length value greater than the actual domain name… | |
| Modificada | Media (5.3) | 0.47% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter. | |
| Modificada | Media (5.3) | 0.34% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive. | |
| Modificada | Crítica (9.8) | 0.61% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter. | |
| Modificada | Alta (7.8) | 0.24% | — | Amazon Freertos | 7/3/2024 | 17/6/2026 | FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist that allows code injection and execution. These issues affect ARMv7-M MPU ports,… | |
| Modificada | Crítica (9.8) | 1.3% | — | Microsoft Azure Rtos Threadx | 5/12/2023 | 17/6/2026 | Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arbitrary read and write due to vulnerability in parameter checking mechanism in Azure RTOS ThreadX, which may lead to privilege escalation. The affected components include… | |
| Modificada | Crítica (9.8) | 3.1% | — | Microsoft Azure Rtos Netx DUO | 5/12/2023 | 17/6/2026 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to icmp, tcp, snmp, dhcp, nat… | |
| Modificada | Crítica (9.8) | 3.1% | — | Microsoft Azure Rtos Netx DUO | 5/12/2023 | 17/6/2026 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause an out-of-bounds write in Azure RTOS NETX Duo, that could lead to remote code execution. The affected components include process related to IGMP protocol in RTOS v6.2.1 and… | |
| Modificada | Crítica (9.8) | 4.3% | — | Microsoft Azure Rtos Netx DUO | 5/12/2023 | 17/6/2026 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to snmp, smtp, ftp and dtls in… | |
| Modificada | Crítica (9.8) | 3.9% | — | Microsoft Azure Rtos Netx DUO | 5/12/2023 | 17/6/2026 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions related to ftp and sntp in RTOS v6.2.1… | |
| Modificada | Alta (7.8) | 0.28% | — | Amazon FreertosTI Simplelink Cc13xx Software Development KITTI Simplelink Cc26xx Software Development KITTI Simplelink Cc32xx Software Development KIT+2 | 21/11/2023 | 17/6/2026 | Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code execution. | |
| Modificada | Alta (7.8) | 0.76% | — | Microsoft Azure Rtos Guix Studio | 10/10/2023 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.33% | — | IllumosOmniosce OmniosOpenindianaJoyent Smartos+1 | 26/12/2022 | 17/6/2026 | An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is… | |
| Modificada | Alta (7.8) | 0.80% | — | Microsoft Azure Rtos Guix Studio | 9/11/2022 | 10/8/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.89% | — | Microsoft Azure Rtos Filex | 8/11/2022 | 17/6/2026 | Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory contents. When a valid log file with… | |
| Modificada | Crítica (9.8) | 2.1% | — | Microsoft Azure Rtos Usbx | 4/11/2022 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker… | |
| Modificada | Crítica (9.8) | 1.1% | — | ARM Cmsis-rtos | 3/5/2022 | 17/6/2026 | ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution. | |
| Modificada | Alta (7.8) | 0.34% | — | Amazon Freertos | 17/11/2021 | 17/6/2026 | FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ability to execute injected code to achieve further privilege… | |
| Modificada | Media (4.6) | 1.1% | — | Microsoft Azure Rtos | 10/11/2021 | 19/8/2026 | Azure RTOS Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 0.99% | — | Hilscher RCX RtosPepperl-fuchs Ice1-16di-g60l-v1d FirmwarePepperl-fuchs Ice1-16dio-g60l-c1-v1d FirmwarePepperl-fuchs Ice1-16dio-g60l-v1d Firmware+5 | 13/5/2021 | 17/6/2026 | In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device. | |
| Modificada | Crítica (9.8) | 1.3% | — | Amazon Freertos | 3/5/2021 | 17/6/2026 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory. | |
| Modificada | Crítica (9.8) | 1.4% | — | Amazon Freertos | 22/4/2021 | 17/6/2026 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer. | |
| Modificada | Crítica (9.8) | 1.4% | — | Amazon Freertos | 22/4/2021 | 17/6/2026 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation. |