Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 16% | — | Hcomm Xpient Iris | 28/1/2020 | 16/6/2026 | Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer. | |
| Modificada | Crítica (9.8) | 5.1% | — | Iris Citations Management Tool Project Iris Citations Management Tool | 25/1/2020 | 16/6/2026 | IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5.5) | 0.29% | — | Lavamobiles Iris 88 Lite Firmware | 14/11/2019 | 17/6/2026 | The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system… | |
| Modificada | Media (5.5) | 0.29% | — | Lavamobiles Iris 88 Firmware | 14/11/2019 | 17/6/2026 | The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Iris 88 Firmware | 14/11/2019 | 17/6/2026 | The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Iris 88 Firmware | 14/11/2019 | 17/6/2026 | The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically… | |
| Modificada | Media (6.1) | 0.65% | — | Systematicinc Iris Standards Management | 12/11/2019 | 17/6/2026 | Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a malicious user to conduct a Cross Site Scripting attack against users of the application. | |
| Modificada | Crítica (9.8) | 1.4% | — | Systematic Iris Webforms | 12/11/2019 | 17/6/2026 | Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication. | |
| Modificada | Media (5.3) | 1.3% | — | Systematic Iris Webforms | 12/11/2019 | 17/6/2026 | Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exists. | |
| Modificada | Crítica (9.8) | 31% | — | Socomec Diris A-40 Firmware | 9/10/2019 | 17/6/2026 | Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI. | |
| Modificada | Crítica (9.8) | 2.3% | — | Irisnet-crypto | 25/2/2019 | 17/6/2026 | In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage. | |
| Modificada | Crítica (9.8) | 5.6% | — | Wiris Mathtype | 28/2/2018 | 17/6/2026 | An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a function call with an invalid parameter, and a subsequent free of important data such as a function pointer or list pointer. This is fixed in 6.9d. | |
| Modificada | Crítica (9.8) | 3.9% | — | Wiris Mathtype | 28/2/2018 | 17/6/2026 | A Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of a linked list. This is fixed in 6.9d. | |
| Modificada | Crítica (9.8) | 3.6% | — | Wiris Mathtype | 28/2/2018 | 17/6/2026 | An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d. | |
| Modificada | Crítica (9.8) | 3.9% | — | Wiris Mathtype | 28/2/2018 | 17/6/2026 | A stack-based buffer overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. This occurs in a function call in which the first argument is a corrupted offset value and the second argument is a stack buffer. This is fixed in 6.9d. | |
| Modificada | Media (5.3) | 1.0% | — | Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+4 | 20/2/2018 | 17/6/2026 | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default. | |
| Modificada | Media (5.3) | 1.0% | — | Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+4 | 20/2/2018 | 17/6/2026 | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory. | |
| Modificada | Crítica (9.8) | 1.1% | — | Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+4 | 20/2/2018 | 17/6/2026 | Datto ALTO and SIRIS devices have a default VNC password. | |
| Modificada | Crítica (9.8) | 2.8% | — | Datto Alto 3 FirmwareDatto Alto 2 FirmwareDatto Alto XL FirmwareDatto Siris 3 Firmware+4 | 20/2/2018 | 17/6/2026 | Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts. | |
| Modificada | Media (6.5) | 0.84% | — | Symantec Altiris Deployment Solution | 19/2/2018 | 16/6/2026 | DBManager in Symantec Altiris Deployment Solution 6.9.x before DS 6.9 SP4 allows remote attackers to cause a denial of service via a crafted request. | |
| Modificada | Crítica (9.8) | 5.3% | — | Shindiristudio Content Timeline | 29/9/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php. | |
| Modificada | Media (5.5) | 0.33% | — | Symantec Altiris IT Management Suite | 20/4/2016 | 17/6/2026 | The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local users to bypass intended application-blacklist restrictions via unspecified vectors. | |
| Modificada | Media (6.8) | 1.2% | — | Symantec Altiris Wise Package Studio | 17/3/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Symantec Altiris WISE Package Studio before 8.0MR1 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 7.1% | — | Symantec PcanywhereSymantec Altiris Client Management Suite Pcanywhere SolutionSymantec Altiris Climentent Manage Suite Pcanywhere SolutionSymantec Altiris Deployment Solution Remote Pcanywhere Solution+1 | 8/3/2012 | 16/6/2026 | The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and… | |
| Modificada | Media (5) | 2.6% | — | Symantec PcanywhereSymantec Altiris Client Management Suite Pcanywhere SolutionSymantec Altiris Deployment Solution Remote Pcanywhere SolutionSymantec Altiris IT Management Suite Pcanywhere Solution | 22/2/2012 | 16/6/2026 | Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allow remote… |