Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.43% | — | Wp-sentry Project Wp-sentry | 27/6/2022 | 17/6/2026 | The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well | |
| Modificada | Alta (8.8) | 5.2% | — | IWT Facesentry Access Control System Firmware | 4/5/2021 | 17/6/2026 | iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user via the 'strInIP' POST parameter in pingTest PHP script. | |
| Modificada | Alta (7.5) | 0.60% | — | Sentrysoftware Hardware Sentry KM FOR BMC Patrol | 23/4/2021 | 17/6/2026 | In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout of a command. | |
| Modificada | Alta (8.8) | 1.7% | — | Pelco Digital Sentry Server | 16/2/2021 | 17/6/2026 | The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stack-based buffer overflow. This can be exploited by a remote attacker to potentially execute arbitrary attacker-supplied code. The victim would have to visit a malicious webpage using Internet Explorer… | |
| Modificada | Alta (8.1) | 0.79% | — | Pelco Digital Sentry Server | 12/2/2021 | 17/6/2026 | DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid="… | |
| Modificada | Alta (7.5) | 1.6% | — | Pelco Digital Sentry Server | 11/2/2021 | 17/6/2026 | Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is… | |
| Analizada | Alta (7.5) | 1.5% | — | Telestream MediusTelestream Sentry | 22/9/2020 | 17/6/2026 | Telestream Tektronix Medius before 10.7.5 and Sentry before 10.7.5 have a SQL injection vulnerability allowing an unauthenticated attacker to dump database contents via the page parameter in a page=login request to index.php (aka the server login page). | |
| Modificada | Alta (7.5) | 2.2% | — | Mobileiron CloudMobileiron CoreMobileiron Enterprise ConnectorMobileiron Reporting Database+1 | 7/7/2020 | 17/6/2026 | An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to read files on the system via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.8% | — | Mobileiron CloudMobileiron CoreMobileiron Enterprise ConnectorMobileiron Reporting Database+1 | 7/7/2020 | 17/6/2026 | An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to bypass authentication mechanisms via unspecified vectors. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Mobileiron CoreMobileiron Enterprise ConnectorMobileiron Monitor AND Reporting DatabaseMobileiron Sentry | 7/7/2020 | 17/6/2026 | A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote… | |
| Modificada | Crítica (9.8) | 1.4% | — | Mobileiron SentryMobileiron Virtual Smartphone Platform | 13/2/2020 | 17/6/2026 | MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme. | |
| Modificada | Alta (7.5) | 1.5% | — | ATT Mobileiron SentryATT Mobileiron Virtual Smartphone Platform | 12/2/2020 | 17/6/2026 | MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm | |
| Modificada | Crítica (9.1) | 4.0% | — | Mobileiron Virtual Smartphone PlatformMobileiron Sentry | 8/1/2020 | 17/6/2026 | MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords | |
| Modificada | Alta (8.8) | 1.3% | — | Apache Sentry | 23/8/2018 | 17/6/2026 | An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1. This can allow an attacker unauthorized access to the partitioned data of a Sentry protected table and can allow an attacker to remove data from a Sentry protected table. | |
| Modificada | Crítica (9.8) | 1.5% | — | Tnlsoftsolutions Sentry Vision | 29/3/2018 | 17/6/2026 | The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side. | |
| Modificada | Media (6.1) | 0.63% | — | Netikus Eventsentry | 10/4/2017 | 17/6/2026 | Netikus EventSentry before 3.2.1.44 has XSS via SNMP. | |
| Modificada | Alta (8.8) | 3.3% | — | Apache Sentry | 19/8/2016 | 17/6/2026 | Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) reflect, (2) reflect2, or (3) java_method Hive builtin functions. | |
| Modificada | Crítica (9.8) | 5.8% | — | Schneider-electric Pelco Digital Sentry Video Management System Firmware | 15/7/2016 | 17/6/2026 | Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardcoded credentials, which allows remote attackers to obtain access, and consequently execute arbitrary code, via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.0% | — | K7computing K7sentry.sysK7computing Anti-virus PlusK7computing Total SecurityK7computing Ultimate Security | 6/2/2015 | 17/6/2026 | K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call. | |
| Modificada | Media (4.3) | 1.5% | — | Eventsentry | 23/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet. | |
| Modificada | Media (5) | 2.4% | — | Getsentry Raven-ruby | 20/1/2015 | 17/6/2026 | The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number. | |
| Modificada | Alta (7.2) | 0.63% | — | K7computing K7av Sentry Device Driver | 12/12/2014 | 17/6/2026 | Stack-based buffer overflow in the K7Sentry.sys kernel mode driver (aka K7AV Sentry Device Driver) before 12.8.0.119, as used in multiple K7 Computing products, allows local users to execute arbitrary code with kernel privileges via unspecified vectors. | |
| Modificada | Media (4.9) | 0.47% | — | K7computing K7av Sentry Device Driver | 12/12/2014 | 17/6/2026 | The K7Sentry.sys kernel mode driver (aka K7AV Sentry Device Driver) before 12.8.0.119, as used in multiple K7 Computing products, allows local users to cause a denial of service (NULL pointer dereference) as demonstrated by a filename containing "crashme$$". | |
| Modificada | Media (5) | 2.1% | — | Bradfordnetworks Network Sentry Appliance SoftwareBradfordnetworks Network Sentry Appliance | 13/6/2012 | 16/6/2026 | The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack. | |
| Modificada | Media (6.8) | 0.76% | — | Bradfordnetworks Network Sentry Appliance SoftwareBradfordnetworks Network Sentry Appliance | 13/6/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote attackers to hijack the authentication of administrators for requests that (1) insert XSS sequences or (2) send messages to clients. |