Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)4.6%💥 PoCLibexpat Project LibexpatNetapp Clustered Data OntapNetapp Oncommand Workflow AutomationTenable Nessus+324/1/202217/6/2026
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
ModificadaAlta (8.8)2.8%—Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server10/1/202217/6/2026
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
ModificadaAlta (8.8)2.8%—Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server10/1/202217/6/2026
nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
ModificadaAlta (8.8)2.6%—Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server10/1/202217/6/2026
lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
ModificadaCrítica (9.8)3.4%—Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server10/1/202217/6/2026
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
ModificadaCrítica (9.8)3.4%—Libexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server10/1/202217/6/2026
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
ModificadaCrítica (9.8)4.8%💥 PoCLibexpat Project LibexpatTenable NessusSiemens Sinema Remote Connect ServerDebian Linux10/1/202217/6/2026
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
ModificadaAlta (7.8)3.8%💥 PoCLibexpat Project LibexpatNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Baseboard Management Controller+46/1/202217/6/2026
In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
ModificadaAlta (8.8)4.2%💥 PoCLibexpat Project LibexpatTenable NessusDebian LinuxSiemens Sinema Remote Connect Server+41/1/202217/6/2026
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).
ModificadaAlta (7.5)5.3%—StrongswanDebian LinuxFedoraproject FedoraSiemens Sinema Remote Connect Server+2118/10/202117/6/2026
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but…
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaAlta (7.5)65%—Apache Http ServerFedoraproject FedoraDebian LinuxNetapp Cloud Backup+1416/9/202117/6/2026
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaMedia (4.3)0.36%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipulate certain parameters and set a valid user of the affected software as invalid (or vice-versa).
ModificadaMedia (4.3)0.36%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve a list of network devices a known user can manage.
ModificadaMedia (4.3)0.38%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.
ModificadaMedia (4.3)0.36%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for a known user.
ModificadaMedia (6.5)0.37%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software allows sending send-to-sleep notifications to the managed devices. An unauthenticated attacker in the same network of the affected system can abuse these notifications to cause a Denial-of-Service…
ModificadaMedia (6.5)0.39%—Siemens Sinema Remote Connect Server14/9/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be manipulated by an unauthenticated attacker in the same network of the affected system.
ModificadaAlta (7.8)0.24%—Siemens Sinema Remote Connect19/8/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privileges and execute own code on the device.
ModificadaMedia (5.3)4.9%—Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+165/8/202117/6/2026
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to…
ModificadaBaja (3.7)6.3%💥 PoCHaxx LibcurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+295/8/202117/6/2026
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing…
ModificadaCrítica (9.1)33%—Wibu CodemeterSiemens PSS CapeSiemens Sicam 230 FirmwareSiemens Simatic Information Server+616/6/202117/6/2026
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
ModificadaAlta (8.8)0.90%—Siemens Sinema Remote Connect Server15/3/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integrity and gain information from logs and templates of the service.
ModificadaAlta (8.8)0.97%—Siemens Sinema Remote Connect Server15/3/202117/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization server could be changed to add a rogue server by an attacker authenticating with unprivilege user…
ModificadaAlta (7.5)7.8%—Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+2021/1/202017/6/2026
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
Orbitaley — Vulnerabilidades