Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
–

2289 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.8)0.33%—Pingidentity PingfederatePingidentity Pingid Adapter FOR PingfederatePingidentity Pingid Integration KIT25/4/202317/6/2026
A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID mobile authenticators is vulnerable to pre-computed dictionary attacks, leading to a bypass of offline MFA.
ModificadaAlta (7.2)2.1%💥 PoCSmartptt Scada14/4/202317/6/2026
SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default).
ModificadaAlta (8.8)1.6%—Scada-lts10/4/202317/6/2026
An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile.
ModificadaMedia (6.1)0.40%—Redhat Keycloak Node.js AdapterRedhat Single Sign-on27/3/202317/6/2026
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function.
ModificadaAlta (7.5)0.99%—Radare223/3/202317/6/2026
Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.
ModificadaAlta (7.5)0.72%—Cisco Adaptive Security ApplianceCisco Secure Firewall Threat Defense23/3/202311/8/2026
A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote…
ModificadaMedia (5.9)0.68%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat DefenseCisco IOSCisco IOS XE23/3/202311/8/2026
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.…
ModificadaAlta (7.2)0.74%—IBM Qradar Security Information AND Event Manager22/3/202317/6/2026
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425.
ModificadaCrítica (9.8)0.68%—Aveva Plant ScadaAveva Telemetry Server16/3/202317/6/2026
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
ModificadaMedia (5.5)0.31%—Radare210/3/202317/6/2026
radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.
ModificadaCrítica (9.8)0.65%—Inscada Project Inscada6/3/202317/6/2026
Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Account Footprinting. This issue affects inSCADA: before 20230115-1.
ModificadaMedia (6.1)0.88%💥 ExploitShortpixel Adaptive Images27/2/202317/6/2026
The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin
ModificadaMedia (5.3)0.42%—Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202124/2/202317/6/2026
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo…
ModificadaAlta (7.5)0.39%—IBM Qradar Security Information AND Event Manager17/2/202317/6/2026
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402.
ModificadaAlta (7.8)0.17%—Administrative Tools FOR Intel Network AdaptersIntel Non-volatile Memory Update Utility16/2/202317/6/2026
Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.19%—Intel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 FirmwareIntel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Controller X710-am2 Firmware+1116/2/202317/6/2026
Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.19%—Administrative Tools FOR Intel Network Adapters16/2/202317/6/2026
Insufficient control flow management in some Intel(R) Ethernet Controller Administrative Tools drivers for Windows before version 1.5.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.4)0.68%—Fujitsu Tsclinical Define.xml GeneratorFujitsu Tsclinical Metadata Desktop Tools15/2/202317/6/2026
Existe una restricción inadecuada de la vulnerabilidad de referencia de entidad externa XML (XXE) en tsClinical Define.xml Generator todas las versiones (v1.0.0 a v1.4.0) y tsClinical Metadata Desktop Tools versión 1.0.3 a versión 1.1.0. Si se aprovecha esta vulnerabilidad, un atacante puede obtener un archivo…
ModificadaCrítica (9.8)2.1%—Schneider-electric Interactive Graphical Scada System1/2/202317/6/2026
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to…
ModificadaCrítica (9.8)1.2%—Schneider-electric Interactive Graphical Scada System1/2/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)
ModificadaAlta (7.5)0.57%—Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202131/1/202317/6/2026
Existe una vulnerabilidad CWE-200: Exposición de información confidencial a un actor no autorizado que podría provocar la divulgación de información cuando se envían mensajes específicos al servidor a través del puerto TCP del servidor de la base de datos. Productos afectados: EcoStruxure Geo SCADA Expert 2019 - 2021…
ModificadaAlta (7.5)0.57%—Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202131/1/202317/6/2026
Existe una vulnerabilidad CWE-863: autorización incorrecta que podría causar denegación de servicio contra el servidor Geo SCADA cuando se envían mensajes específicos al servidor a través del puerto TCP del servidor de base de datos.
ModificadaMedia (6.5)0.71%—Changingtec Megaservisignadapter31/1/202317/6/2026
El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de lectura fuera de los límites debido a una validación insuficiente de la longitud del parámetro. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder a contenido confidencial parcial en la memoria e interrumpir…
ModificadaCrítica (9.8)0.91%—Changingtec Megaservisignadapter31/1/202317/6/2026
El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de validación de entrada incorrecta. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder y modificar la subclave HKEY_CURRENT_USER (por ejemplo, AutoRUN) en el Registro, donde se pueden ejecutar scripts maliciosos…
ModificadaAlta (7.5)1.00%—Changingtec Megaservisignadapter31/1/202317/6/2026
El componente ChangingTech MegaServiSignAdapter tiene una vulnerabilidad de path traversal dentro de su función de lectura de archivos. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para acceder a archivos arbitrarios del sistema.