Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
2289 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 0.33% | — | Pingidentity PingfederatePingidentity Pingid Adapter FOR PingfederatePingidentity Pingid Integration KIT | 25/4/2023 | 17/6/2026 | A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA. | |
| Modificada | Alta (7.2) | 2.1% | 💥 PoC | Smartptt Scada | 14/4/2023 | 17/6/2026 | SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default). | |
| Modificada | Alta (8.8) | 1.6% | — | Scada-lts | 10/4/2023 | 17/6/2026 | An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile. | |
| Modificada | Media (6.1) | 0.40% | — | Redhat Keycloak Node.js AdapterRedhat Single Sign-on | 27/3/2023 | 17/6/2026 | A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function. | |
| Modificada | Alta (7.5) | 0.99% | — | Radare2 | 23/3/2023 | 17/6/2026 | Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6. | |
| Modificada | Alta (7.5) | 0.72% | — | Cisco Adaptive Security ApplianceCisco Secure Firewall Threat Defense | 23/3/2023 | 11/8/2026 | A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote… | |
| Modificada | Media (5.9) | 0.68% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco IOSCisco IOS XE | 23/3/2023 | 11/8/2026 | A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.… | |
| Modificada | Alta (7.2) | 0.74% | — | IBM Qradar Security Information AND Event Manager | 22/3/2023 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425. | |
| Modificada | Crítica (9.8) | 0.68% | — | Aveva Plant ScadaAveva Telemetry Server | 16/3/2023 | 17/6/2026 | The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states. | |
| Modificada | Media (5.5) | 0.31% | — | Radare2 | 10/3/2023 | 17/6/2026 | radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c. | |
| Modificada | Crítica (9.8) | 0.65% | — | Inscada Project Inscada | 6/3/2023 | 17/6/2026 | Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Account Footprinting. This issue affects inSCADA: before 20230115-1. | |
| Modificada | Media (6.1) | 0.88% | 💥 Exploit | Shortpixel Adaptive Images | 27/2/2023 | 17/6/2026 | The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin | |
| Modificada | Media (5.3) | 0.42% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 2021 | 24/2/2023 | 17/6/2026 | A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo… | |
| Modificada | Alta (7.5) | 0.39% | — | IBM Qradar Security Information AND Event Manager | 17/2/2023 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402. | |
| Modificada | Alta (7.8) | 0.17% | — | Administrative Tools FOR Intel Network AdaptersIntel Non-volatile Memory Update Utility | 16/2/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.19% | — | Intel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 FirmwareIntel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Controller X710-am2 Firmware+11 | 16/2/2023 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Administrative Tools FOR Intel Network Adapters | 16/2/2023 | 17/6/2026 | Insufficient control flow management in some Intel(R) Ethernet Controller Administrative Tools drivers for Windows before version 1.5.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.4) | 0.68% | — | Fujitsu Tsclinical Define.xml GeneratorFujitsu Tsclinical Metadata Desktop Tools | 15/2/2023 | 17/6/2026 | Existe una restricción inadecuada de la vulnerabilidad de referencia de entidad externa XML (XXE) en tsClinical Define.xml Generator todas las versiones (v1.0.0 a v1.4.0) y tsClinical Metadata Desktop Tools versión 1.0.3 a versión 1.1.0. Si se aprovecha esta vulnerabilidad, un atacante puede obtener un archivo… | |
| Modificada | Crítica (9.8) | 2.1% | — | Schneider-electric Interactive Graphical Scada System | 1/2/2023 | 17/6/2026 | A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.8) | 1.2% | — | Schneider-electric Interactive Graphical Scada System | 1/2/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073) | |
| Modificada | Alta (7.5) | 0.57% | — | Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 2021 | 31/1/2023 | 17/6/2026 | Existe una vulnerabilidad CWE-200: Exposición de información confidencial a un actor no autorizado que podría provocar la divulgación de información cuando se envían mensajes específicos al servidor a través del puerto TCP del servidor de la base de datos. Productos afectados: EcoStruxure Geo SCADA Expert 2019 - 2021… | |
| Modificada | Alta (7.5) | 0.57% | — | Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 2021 | 31/1/2023 | 17/6/2026 | Existe una vulnerabilidad CWE-863: autorización incorrecta que podría causar denegación de servicio contra el servidor Geo SCADA cuando se envían mensajes específicos al servidor a través del puerto TCP del servidor de base de datos. | |
| Modificada | Media (6.5) | 0.71% | — | Changingtec Megaservisignadapter | 31/1/2023 | 17/6/2026 | El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de lectura fuera de los límites debido a una validación insuficiente de la longitud del parámetro. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder a contenido confidencial parcial en la memoria e interrumpir… | |
| Modificada | Crítica (9.8) | 0.91% | — | Changingtec Megaservisignadapter | 31/1/2023 | 17/6/2026 | El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de validación de entrada incorrecta. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder y modificar la subclave HKEY_CURRENT_USER (por ejemplo, AutoRUN) en el Registro, donde se pueden ejecutar scripts maliciosos… | |
| Modificada | Alta (7.5) | 1.00% | — | Changingtec Megaservisignadapter | 31/1/2023 | 17/6/2026 | El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de path traversal dentro de su función de lectura de archivos. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder a archivos arbitrarios del sistema. |