Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

209 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.29%—Tidaweb Tida URL Screenshot29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tidaweb Tida URL Screenshot tida-url-screenshot allows Reflected XSS.This issue affects Tida URL Screenshot: from n/a through <= 1.0.1.
AnalizadaAlta (7.8)0.17%—Lenovo Lock Screen11/10/202417/6/2026
A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.
AnalizadaAlta (8.5)0.42%—Deltaww Diascreen6/8/202417/6/2026
A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.
AplazadaAlta (8.5)0.23%—Point B LTD Getscreen AgentAI1/8/202417/6/2026
A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulation leads to creation of temporary file with insecure permissions. Local access…
AplazadaAlta (8)0.28%—Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI7/6/202417/6/2026
Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges.
AplazadaAlta (8.8)0.32%—Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI7/6/202417/6/2026
Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information.
AplazadaAlta (8.8)0.32%—Precor Touchscreen Console P82AI7/6/202417/6/2026
Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges.
AplazadaAlta (7.8)0.20%—Precor Touchscreen Console P62AIPrecor Touchscreen Console P80AIPrecor Touchscreen Console P82AI7/6/202417/6/2026
Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, because there is a hard-coded service code.
AplazadaMedia (6.5)0.35%—Petri Damsten Fullscreen GalleriaAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Petri Damstén Fullscreen Galleria allows Stored XSS.This issue affects Fullscreen Galleria: from n/a through 1.6.11.
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitConnectwise Screenconnect21/2/202417/6/2026
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
AnalizadaAlta (8.4)95%⚠ Explotación activa💥 ExploitConnectwise Screenconnect21/2/202417/6/2026
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
ModificadaMedia (4.3)0.22%—Cochinoman Splashscreen12/2/202417/6/2026
The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaAlta (8.1)1.0%—Connectwise AutomateConnectwise Screenconnect1/2/202417/6/2026
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
ModificadaMedia (5.5)0.45%—Connectwise AutomateConnectwise Screenconnect1/2/202417/6/2026
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
ModificadaMedia (6.5)0.46%—Qualys WEB Application Screening9/1/202417/6/2026
Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to configure or edit jobs to utilize the plugin and…
ModificadaAlta (8.8)0.21%—Nazmulhossainnihal Login Screen Manager6/11/202317/6/2026
Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions.
ModificadaMedia (4.8)0.38%—Login Screen Manager Project Login Screen Manager31/10/202317/6/2026
The Login Screen Manager WordPress plugin through 3.5.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaAlta (7.8)0.23%—Deltaww Diascreen21/9/202317/6/2026
Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file. This could allow an attacker to execute code in the context of the current process.
ModificadaAlta (8.1)0.43%—Selinc Sel-5036 Acselerator BAY Screen Builder31/8/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering Laboratories SEL-5036 acSELerator Bay Screen Builder Software on Windows allows Relative Path Traversal. SEL acSELerator Bay Screen Builder software is distributed by SEL-5033 SEL acSELerator RTAC,…
ModificadaAlta (7.8)0.22%—Jtekt Screen Creator Advance 211/4/202317/6/2026
Screen Creator Advance 2 Ver.0.1.1.4 Build01A and earlier is vulnerable to improper restriction of operations within the bounds of a memory buffer (CWE-119) due to improper check of its data size when processing a project file. If a user of Screen Creator Advance 2 opens a specially crafted project file, information…
ModificadaMedia (6.5)0.54%💥 ExploitGNU Screen8/4/202317/6/2026
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
ModificadaAlta (7.8)0.89%—Jtekt Screen Creator Advance 229/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of KOYO Screen Creator 0.1.1.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SCA2 files.…
ModificadaAlta (7.5)0.50%—Screencheck Badgemaker15/2/202317/6/2026
Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain credentials for authentication via network sniffing.
ModificadaAlta (7.8)0.29%—Jtekt Screen Creator Advance 213/2/202317/6/2026
Use-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even when an error was detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.
ModificadaAlta (7.8)0.31%—Jtekt Screen Creator Advance 213/2/202317/6/2026
Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing control management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or…
Orbitaley — Vulnerabilidades