Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.3) | 0.20% | — | Devolutions Remote Desktop Manager | 8/1/2026 | 17/6/2026 | Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing. | |
| Analizada | Alta (7.5) | 0.40% | — | Dwyeromega Isensix Advanced Remote Monitoring System Firmware | 6/1/2026 | 17/6/2026 | DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and… | |
| Analizada | Media (4.3) | 0.25% | — | Siemens Sinema Remote Connect Server | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This… | |
| Analizada | Baja (3.3) | 0.10% | — | Siemens Sinema Remote Connect Server | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server… | |
| Analizada | Alta (8.9) | 1.3% | — | Remotecontrolio Remote Keyboard Desktop | 4/12/2025 | 17/6/2026 | Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution. | |
| Aplazada | Alta (8.5) | 0.19% | — | Jumpcloud Remote AssistAI | 2/12/2025 | 17/6/2026 | JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\SYSTEM during agent uninstall or update operations. The Remote Assist uninstaller performs privileged create, write, execute, and delete actions on predictable files… | |
| Analizada | Alta (7.5) | 0.39% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+13 | 1/12/2025 | 17/6/2026 | An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition. | |
| Analizada | Media (6.5) | 0.39% | — | Devolutions ServerDevolutions Remote Desktop Manager | 28/11/2025 | 17/6/2026 | Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0. | |
| Aplazada | Alta (8.5) | 0.17% | — | Remotecall Remote Support ProgramAI | 15/10/2025 | 17/6/2026 | RemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Aplazada | Alta (8.5) | 0.17% | — | Remotecall Remote Support ProgramAI | 15/10/2025 | 17/6/2026 | RemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Aplazada | Alta (8.5) | 0.17% | — | Remoteview PC Application ConsoleAI | 15/10/2025 | 17/6/2026 | RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution. | |
| Analizada | Alta (8.8) | 0.60% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+14 | 14/10/2025 | 17/6/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.12% | — | IBM Infosphere Data Replication Vsam FOR Z/os Remote Source | 7/10/2025 | 17/6/2026 | IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system. | |
| Aplazada | Media (4.7) | 0.14% | — | Teamviewer RemoteAITeamviewer TensorAI | 1/10/2025 | 17/6/2026 | Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local, unprivileged access to a device lacking adequate malware protection to escalate privileges by spoofing the update file path. This may… | |
| Aplazada | Alta (7.6) | 0.25% | — | Click Plus C2-03cpu2AIClick Plus Remote PLCAI | 23/9/2025 | 17/6/2026 | An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC application, authenticated users with low-level access permissions can exploit this vulnerability to read and modify PLC variables beyond their… | |
| Aplazada | Media (4.3) | 0.20% | — | User Sync Remote User SyncAI | 17/9/2025 | 25/9/2026 | The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the mo_user_sync_form_handler() function. This makes it possible for unauthenticated attackers to deactivate the plugin… | |
| Aplazada | Media (6.4) | 0.20% | — | Auto Save Remote Images DraftsAI | 10/9/2025 | 17/6/2026 | The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the fetch_images() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Crítica (10) | 0.73% | — | Xwiki Remote MacrosAI | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the title in the confluence paste code macro allows remote code execution for any user who can edit any page. The classes parameter is… | |
| Aplazada | Crítica (10) | 0.73% | — | Xwiki Remote MacrosAI | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the ac:type in the ConfluenceLayoutSection macro allows remote code execution for any user who can edit any page The classes parameter is… | |
| Aplazada | Media (5.1) | 0.26% | — | RemoteclinicAI | 2/9/2025 | 17/6/2026 | A vulnerability was detected in RemoteClinic 2.0. This vulnerability affects unknown code of the file /staff/profile.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. | |
| Analizada | Media (5.5) | 0.53% | — | Remoteclinic Remote Clinic | 1/9/2025 | 17/6/2026 | A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.php. The manipulation of the argument image results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.39% | — | Remoteclinic Remote Clinic | 1/9/2025 | 17/6/2026 | A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patients/edit-patient.php. The manipulation of the argument Email leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Remoteclinic Remote Clinic | 1/9/2025 | 17/6/2026 | A flaw has been found in RemoteClinic up to 2.0. This vulnerability affects unknown code of the file /staff/edit.php. Executing manipulation of the argument Last Name can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.53% | — | Remoteclinic Remote Clinic | 1/9/2025 | 17/6/2026 | A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Performing manipulation of the argument image results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects products that… | |
| Aplazada | Alta (7.2) | 0.27% | — | Securden Unified PAM Remote Vendor GatewayAI | 25/8/2025 | 17/6/2026 | Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions. |