Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.88% | — | Intel Standard ManageabilityIntel Active Management Technology Firmware | 18/8/2022 | 17/6/2026 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access. | |
| Modificada | Media (6.8) | 0.37% | — | Intel Standard ManageabilityIntel Active Management Technology Firmware | 18/8/2022 | 17/6/2026 | Improper access control in firmware for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Alta (7.5) | 0.83% | — | Chia Network Cat1 Standard | 29/7/2022 | 17/6/2026 | An inflation issue was discovered in Chia Network CAT1 Standard 1.0.0. Previously minted tokens minted on the Chia blockchain using the CAT1 standard can be inflated to an arbitrary extent by any holder of any amount of the token. The total amount of the token can be increased as high as the malicious actor pleases.… | |
| Modificada | Alta (7.5) | 1.7% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption. | |
| Modificada | Alta (7.5) | 2.0% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption. | |
| Modificada | Alta (7.5) | 1.4% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation. | |
| Modificada | Alta (7.5) | 1.7% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials. | |
| Modificada | Alta (7.5) | 1.6% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message. | |
| Modificada | Crítica (9.8) | 2.1% | — | Deno Standard Modules | 11/10/2021 | 17/6/2026 | Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. | |
| Modificada | Alta (7.8) | 0.41% | — | Teradici Pcoip Standard Agent | 21/7/2021 | 17/6/2026 | The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration directory. | |
| Modificada | Alta (8.7) | 1.9% | — | Siemens DK Standard Ethernet Controller Evaluation KIT FirmwareSiemens Ek-ertec 200 Evaulation KIT FirmwareSiemens Ek-ertec 200p Evaluation KIT FirmwareSiemens Ruggedcom Rm1224 Firmware+75 | 13/7/2021 | 17/6/2026 | Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device. | |
| Modificada | Alta (7.5) | 1.9% | — | Opcfoundation Ua-.net-legacyOpcfoundation UA .net Standard Stack | 20/5/2021 | 17/6/2026 | OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow. | |
| Modificada | Alta (7.5) | 1.3% | — | Siemens Simatic NET CP 343-1 Advanced FirmwareSiemens Simatic NET CP 343-1 Lean FirmwareSiemens Simatic NET CP 343-1 Standard Firmware | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Standard (incl. SIPLUS variants) (All versions). Specially crafted packets sent to TCP port 102 could cause a… | |
| Modificada | Media (4.7) | 0.35% | — | Facebook Zstandard | 4/3/2021 | 17/6/2026 | Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties. | |
| Modificada | Media (5.5) | 0.46% | — | Facebook Zstandard | 4/3/2021 | 17/6/2026 | In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties. | |
| Modificada | Media (4.4) | 0.31% | — | Opcfoundation Ua-.netstandard | 16/2/2021 | 17/6/2026 | A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection. | |
| Modificada | Media (5.5) | 0.25% | — | Teradici Pcoip Graphics AgentTeradici Pcoip Standard Agent | 11/2/2021 | 17/6/2026 | Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux prior to version 21.01.0 may log parts of a user's password in the application logs. | |
| Modificada | Media (5.9) | 0.93% | — | Stm32cubef0Stm32cubef1Stm32cubef2Stm32cubef3+18 | 20/1/2021 | 9/7/2026 | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library,… | |
| Modificada | Media (5.9) | 0.87% | — | Ietf Public KEY Cryptography Standards #1Microchip Libraries FOR Applications | 19/1/2021 | 9/7/2026 | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in… | |
| Modificada | Media (5.3) | 1.1% | — | Code-industry Master PDF EditorFoxitsoftware Foxit ReaderFoxitsoftware PhantompdfGonitro Nitro PRO+9 | 7/1/2021 | 17/6/2026 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates… | |
| Modificada | Crítica (9.8) | 3.1% | — | Wago PFC 100 FirmwareWago PFC 200 FirmwareWago Touch Panel 600 Standard FirmwareWago Touch Panel 600 Advanced Firmware+1 | 17/12/2020 | 17/6/2026 | The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx),… | |
| Modificada | Alta (7.5) | 1.5% | — | Intel Active Management Technology FirmwareNetapp Cloud BackupIntel Standard Manageability | 12/11/2020 | 17/6/2026 | Out-of-bounds read in subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Alta (7.5) | 1.5% | — | Intel Active Management Technology FirmwareIntel Standard Manageability | 12/11/2020 | 17/6/2026 | Out-of-bounds read in DHCP subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Intel Active Management Technology FirmwareNetapp Cloud BackupIntel Standard Manageability | 12/11/2020 | 17/6/2026 | Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unauthenticated user to potentially enable escalation of privileges via network access. | |
| Modificada | Crítica (9.8) | 1.9% | — | Intel Standard ManageabilityIntel Active Management Technology FirmwareNetapp Steelstore Cloud Integrated Storage | 10/9/2020 | 17/6/2026 | Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable escalation of privilege via network access. On un-provisioned systems, an authenticated user may… |