Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.72% | — | Broadcom Symantec Siteminder | 28/3/2022 | 16/6/2026 | A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.5) | 2.7% | — | Apache ArtemisNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 4/2/2022 | 17/6/2026 | In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory. | |
| Modificada | Crítica (9.8) | 1.4% | — | Systeminformation | 9/9/2021 | 17/6/2026 | systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix. | |
| Modificada | Crítica (9.8) | 1.9% | — | Systeminformation | 29/4/2021 | 17/6/2026 | systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has been fixed with a parameter check on user input. Please upgrade to version >= 5.6.4. If you cannot upgrade, be sure to… | |
| Analizada | Alta (7.8) | 91% | ⚠ Explotación activa💥 Exploit | SysteminformationApache Cordova | 16/2/2021 | 17/6/2026 | The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround… | |
| Modificada | Alta (7.5) | 3.9% | — | Apache ArtemisNetapp Oncommand Workflow Automation | 27/1/2021 | 17/6/2026 | While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in error. | |
| Modificada | Alta (7.5) | 11% | — | Apache ActivemqApache ArtemisNetapp Oncommand Workflow AutomationDebian Linux+4 | 27/1/2021 | 17/6/2026 | The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no… | |
| Modificada | Alta (8.8) | 2.7% | — | Systeminformation | 16/12/2020 | 17/6/2026 | In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix. | |
| Modificada | Crítica (9.8) | 2.2% | — | Systeminformation | 27/11/2020 | 17/6/2026 | npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The issue is fixed in version 4.30.5. If you cannot upgrade, be sure to check or sanitize service… | |
| Modificada | Alta (7.3) | 2.4% | — | Systeminformation | 26/11/2020 | 17/6/2026 | This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands. | |
| Modificada | Alta (8.8) | 6.7% | — | Systeminformation | 26/10/2020 | 17/6/2026 | This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands. | |
| Modificada | Alta (7.5) | 1.9% | — | Robotemi Temi | 11/8/2020 | 17/6/2026 | Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.4% | — | Robotemi Robox OS | 7/8/2020 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it automatically answer the attacker's calls, granting audio, video, and motor control via unspecified vectors. | |
| Modificada | Crítica (9.1) | 2.1% | — | Robotemi Launcher OS | 7/8/2020 | 17/6/2026 | Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video via unspecified vectors. | |
| Modificada | Media (6.5) | 0.65% | — | Robotemi Temi Firmware | 7/8/2020 | 17/6/2026 | Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access the REST API and MQTT broker used by the temi and send it custom data/requests via unspecified vectors. | |
| Modificada | Media (6.1) | 4.3% | — | Apache Artemis | 20/7/2020 | 17/6/2026 | In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section. | |
| Modificada | Media (5.5) | 0.70% | — | Apache ArtemisNetapp Oncommand Workflow Automation | 26/6/2020 | 17/6/2026 | A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this flaw to read the contents of the… | |
| Modificada | Alta (7.5) | 6.0% | — | Apache ArtemisRedhat HornetqRedhat Jboss Enterprise Application Platform | 7/3/2018 | 17/6/2026 | It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError. | |
| Modificada | Alta (7.2) | 0.94% | — | Sielcosistemi Winlog LiteSielcosistemi Winlog PRO | 13/2/2017 | 17/6/2026 | An issue was discovered in Sielco Sistemi Winlog Lite SCADA Software, versions prior to Version 3.02.01, and Winlog Pro SCADA Software, versions prior to Version 3.02.01. An uncontrolled search path element (DLL Hijacking) vulnerability has been identified. Exploitation of this vulnerability could give an attacker… | |
| Modificada | Alta (7.2) | 6.9% | — | Apache ArtemisRedhat Jboss Enterprise Application Platform | 27/9/2016 | 17/6/2026 | The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute… | |
| Modificada | Alta (10) | 2.1% | — | Morpho Itemiser 3 | 26/7/2014 | 17/6/2026 | Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request. | |
| Modificada | Media (4.3) | 2.6% | — | CA WEB AgentsBroadcom Siteminder | 29/10/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through 12.51, and SiteMinder 6 Web Agents, allows remote attackers to inject arbitrary web script or HTML via vectors involving a " (double quote) character. | |
| Modificada | Alta (7.5) | 1.5% | — | Siteminder Agent FOR Sharepoint 2010Siteminder Federation 12.0Siteminder Federation 12.1Siteminder Federation 12.5+4 | 21/3/2013 | 16/6/2026 | CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Datemill Etano | 6/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) email, (3) email2, (4) f17_zip, or (5) agree parameter to join.php; (6) PATH_INFO, (7) st, (8) f17_city, (9) f17_country, (10) f17_state, (11) f17_zip, (12)… | |
| Modificada | Alta (9.3) | 2.5% | — | Sielcosistemi Winlog PROSielcosistemi Winlog Lite | 19/8/2012 | 16/6/2026 | Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 do not validate the return value of the realloc function, which allows remote attackers to cause a denial of service (invalid 0x00 write operation and daemon crash) or possibly have unspecified other impact via a port-46824 TCP packet… |