Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.43%—Wp-sentry Project Wp-sentry27/6/202217/6/2026
The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well
ModificadaAlta (8.8)5.2%—IWT Facesentry Access Control System Firmware4/5/202117/6/2026
iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' POST parameter in pingTest PHP script.
ModificadaAlta (7.5)0.60%—Sentrysoftware Hardware Sentry KM FOR BMC Patrol23/4/202117/6/2026
In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command.
ModificadaAlta (8.8)1.7%—Pelco Digital Sentry Server16/2/202117/6/2026
The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stack-based buffer overflow. This can be exploited by a remote attacker to potentially execute arbitrary attacker-supplied code. The victim would have to visit a malicious webpage using Internet Explorer…
ModificadaAlta (8.1)0.79%—Pelco Digital Sentry Server12/2/202117/6/2026
DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid="…
ModificadaAlta (7.5)1.6%—Pelco Digital Sentry Server11/2/202117/6/2026
Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is…
AnalizadaAlta (7.5)1.5%—Telestream MediusTelestream Sentry22/9/202017/6/2026
Telestream Tektronix Medius before 10.7.5 and Sentry before 10.7.5 have a SQL injection vulnerability allowing an unauthenticated attacker to dump database contents via the page parameter in a page=login request to index.php (aka the server login page).
ModificadaAlta (7.5)2.2%—Mobileiron CloudMobileiron CoreMobileiron Enterprise ConnectorMobileiron Reporting Database+17/7/202017/6/2026
An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to read files on the system via unspecified vectors.
ModificadaCrítica (9.8)2.8%—Mobileiron CloudMobileiron CoreMobileiron Enterprise ConnectorMobileiron Reporting Database+17/7/202017/6/2026
An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to bypass authentication mechanisms via unspecified vectors.
AnalizadaCrítica (9.8)100%⚠ Explotación activaMobileiron CoreMobileiron Enterprise ConnectorMobileiron Monitor AND Reporting DatabaseMobileiron Sentry7/7/202017/6/2026
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote…
ModificadaCrítica (9.8)1.4%—Mobileiron SentryMobileiron Virtual Smartphone Platform13/2/202017/6/2026
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
ModificadaAlta (7.5)1.5%—ATT Mobileiron SentryATT Mobileiron Virtual Smartphone Platform12/2/202017/6/2026
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
ModificadaCrítica (9.1)4.0%—Mobileiron Virtual Smartphone PlatformMobileiron Sentry8/1/202017/6/2026
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords
ModificadaAlta (8.8)1.3%—Apache Sentry23/8/201817/6/2026
An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker unauthorized access to the partitioned data of a Sentry protected table and can allow an attacker to remove data from a Sentry protected table.
ModificadaCrítica (9.8)1.5%—Tnlsoftsolutions Sentry Vision29/3/201817/6/2026
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.
ModificadaMedia (6.1)0.63%—Netikus Eventsentry10/4/201717/6/2026
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
ModificadaAlta (8.8)3.3%—Apache Sentry19/8/201617/6/2026
Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) reflect, (2) reflect2, or (3) java_method Hive builtin functions.
ModificadaCrítica (9.8)5.8%—Schneider-electric Pelco Digital Sentry Video Management System Firmware15/7/201617/6/2026
Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardcoded credentials, which allows remote attackers to obtain access, and consequently execute arbitrary code, via unspecified vectors.
ModificadaAlta (7.2)1.0%—K7computing K7sentry.sysK7computing Anti-virus PlusK7computing Total SecurityK7computing Ultimate Security6/2/201517/6/2026
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.
ModificadaMedia (4.3)1.5%—Eventsentry23/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.
ModificadaMedia (5)2.4%—Getsentry Raven-ruby20/1/201517/6/2026
The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number.
ModificadaAlta (7.2)0.63%—K7computing K7av Sentry Device Driver12/12/201417/6/2026
Stack-based buffer overflow in the K7Sentry.sys kernel mode driver (aka K7AV Sentry Device Driver) before 12.8.0.119, as used in multiple K7 Computing products, allows local users to execute arbitrary code with kernel privileges via unspecified vectors.
ModificadaMedia (4.9)0.47%—K7computing K7av Sentry Device Driver12/12/201417/6/2026
The K7Sentry.sys kernel mode driver (aka K7AV Sentry Device Driver) before 12.8.0.119, as used in multiple K7 Computing products, allows local users to cause a denial of service (NULL pointer dereference) as demonstrated by a filename containing "crashme$$".
ModificadaMedia (5)2.1%—Bradfordnetworks Network Sentry Appliance SoftwareBradfordnetworks Network Sentry Appliance13/6/201216/6/2026
The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack.
ModificadaMedia (6.8)0.76%—Bradfordnetworks Network Sentry Appliance SoftwareBradfordnetworks Network Sentry Appliance13/6/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote attackers to hijack the authentication of administrators for requests that (1) insert XSS sequences or (2) send messages to clients.