Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.38% | — | Rockwellautomation Factorytalk Vantagepoint | 11/5/2023 | 17/6/2026 | A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could… | |
| Modificada | Alta (8.8) | 0.57% | — | Vantage6 | 4/3/2023 | 17/6/2026 | vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh token is valid indefinitely. The refresh token should get a validity of 24-48 hours. A fix was released in version 3.8.0. | |
| Modificada | Media (6.5) | 0.38% | — | Vantage6 | 1/3/2023 | 17/6/2026 | vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning existing users to a different organizations is currently possible. It may lead to unintended access: if a user from organization A is accidentally assigned to organization B, they will retain their permissions and… | |
| Modificada | Media (6.5) | 0.60% | — | Vantage6 | 1/3/2023 | 17/6/2026 | vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots from obtaining usernames. However, if a wrong password is entered a number of… | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+2696 | 12/12/2022 | 17/6/2026 | Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. | |
| Modificada | Alta (8.8) | 3.5% | — | Rockwellautomation Factorytalk Vantagepoint | 17/10/2022 | 17/6/2026 | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could… | |
| Modificada | Alta (8.8) | 1.4% | — | Rockwellautomation Factorytalk Vantagepoint | 17/10/2022 | 17/6/2026 | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (8.8) | 2.3% | — | HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Enterprise Flow MFP M880z FirmwareHP Color Laserjet Managed Flow MFP M880zm FirmwareHP Color Laserjet Enterprise M455 Firmware+211 | 9/11/2021 | 17/6/2026 | During installation with certain driver software or application packages an arbitrary code execution could occur. | |
| Modificada | Media (6.8) | 0.35% | — | Siemens DCA Vantage Analyzer Firmware | 13/10/2020 | 17/6/2026 | A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Affected devices use a hard-coded password to protect the onboard database. This could allow an attacker to… | |
| Modificada | Media (6.8) | 0.38% | — | Siemens DCA Vantage Analyzer Firmware | 13/10/2020 | 17/6/2026 | A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Improper Access Control could allow an unauthenticated attacker to escape from the restricted environment… | |
| Modificada | Alta (7.5) | 15% | 💥 PoC | UI Unifi ControllerW1.fi HostapdAsus Rt-n11Broadcom Adsl+213 | 8/6/2020 | 17/6/2026 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. | |
| Modificada | Alta (7.8) | 0.37% | — | Lenovo Vantage | 14/4/2020 | 17/6/2026 | A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to execute code with elevated privileges. | |
| Modificada | Media (4.4) | 0.27% | — | Lenovo Vantage | 14/4/2020 | 17/6/2026 | A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the system with elevated privileges. | |
| Modificada | Media (6.5) | 1.5% | — | HP Envy 5000 M2u85a FirmwareHP Envy 5000 M2u85b FirmwareHP Envy 5000 M2u91a FirmwareHP Envy 5000 M2u94b Firmware+4 | 16/3/2020 | 17/6/2026 | A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout. | |
| Modificada | Media (5.3) | 1.4% | — | Labvantage | 17/2/2020 | 17/6/2026 | LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a request, because the response will return an 'Unrecognized Database exception… | |
| Modificada | Media (6.1) | 0.67% | — | Iteris Vantage Velocity Firmware | 17/2/2020 | 17/6/2026 | Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script. | |
| Modificada | Crítica (9.8) | 1.8% | — | Iteris Vantage Velocity Firmware | 17/2/2020 | 17/6/2026 | Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts. | |
| Modificada | Crítica (9.8) | 1.5% | — | Iteris Vantage Velocity Firmware | 17/2/2020 | 17/6/2026 | Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password. | |
| Modificada | Crítica (9.8) | 2.5% | — | Iteris Vantage Velocity Firmware | 17/2/2020 | 17/6/2026 | Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field. | |
| Modificada | Media (4.8) | 0.65% | — | HP Deskjet 2600 4uj28b FirmwareHP Deskjet 2600 V1n01a FirmwareHP Deskjet 2600 V1n08a FirmwareHP Deskjet 2600 Y5h60a Firmware+48 | 9/1/2020 | 17/6/2026 | A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A; HP DeskJet Ink… | |
| Modificada | Media (6.1) | 0.79% | — | Avinetworks AVI Vantage | 20/2/2019 | 17/6/2026 | Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959. | |
| Modificada | Media (4.7) | 0.41% | — | Zteusa ZTE Blade Vantage FirmwareZteusa ZTE Blade Spark FirmwareZteusa ZTE Zmax PRO FirmwareZteusa ZTE Zmax Champ Firmware | 28/12/2018 | 17/6/2026 | The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/release-keys, the ZTE Blade Spark Android device with a build fingerprint of ZTE/Z971/peony:7.1.1/NMF26V/20171129.143111:user/release-keys, the ZTE ZMAX Pro Android device with a build fingerprint of… | |
| Modificada | Media (6.6) | 0.53% | — | Canonical Ubuntu LinuxOrcamo Online Receipt Computer Advantage | 7/9/2018 | 17/6/2026 | Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. |