Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.31% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing parts management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or… | |
| Modificada | Alta (7.8) | 0.33% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing screen management information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or… | |
| Modificada | Alta (7.8) | 0.33% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing file structure information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or… | |
| Modificada | Alta (7.8) | 0.33% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound read vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier because the end of data cannot be verified when processing template information. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary code… | |
| Modificada | Alta (7.8) | 0.26% | — | Jtekt Screen Creator Advance 2 | 13/2/2023 | 17/6/2026 | Out-of-bound write vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process when out of specification errors are detected. Having a user of Screen Creator Advance 2 to open a specially crafted project file may lead to information disclosure and/or arbitrary… | |
| Modificada | Alta (7.8) | 0.30% | — | Deltaww Diascreen | 8/2/2023 | 17/6/2026 | Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restrictions of operations within memory, which could allow an attacker to remotely execute arbitrary code. | |
| Modificada | Alta (7.8) | 2.0% | — | Deltaww Diascreen | 8/2/2023 | 17/6/2026 | Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.25% | — | Deltaww Diascreen | 8/2/2023 | 17/6/2026 | Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Alta (7.8) | 4.9% | — | Deltaww CncsoftDeltaww Screeneditor | 3/2/2023 | 17/6/2026 | All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.20% | — | Zebra Enterprise Home Screen | 10/1/2023 | 17/6/2026 | An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and SD card) but it is still possible to use a physical connection (Ethernet cable) without restriction. | |
| Modificada | Media (5.5) | 0.19% | — | Zebra Enterprise Home Screen | 10/1/2023 | 17/6/2026 | An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unauthorized application via a downloaded APK. | |
| Modificada | Alta (7.1) | 0.19% | — | Zebra Enterprise Home Screen | 10/1/2023 | 17/6/2026 | An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use several other applications that are restricted by the admin. | |
| Modificada | Media (4.3) | 0.56% | — | Jenkins Screenrecorder | 19/10/2022 | 17/6/2026 | Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download. | |
| Modificada | Crítica (9.8) | 0.61% | — | Samsung Dynamic Lockscreen | 7/10/2022 | 17/6/2026 | Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api. | |
| Modificada | Media (5.3) | 0.62% | — | Connectwise Screenconnect | 28/9/2022 | 17/6/2026 | ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the default configuration. Attackers could exploit this vulnerability to gain unauthorized access by repeatedly attempting access code… | |
| Modificada | Media (4.8) | 0.59% | — | Dwbooster Loading Page With Loading Screen | 17/7/2022 | 17/6/2026 | The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.6) | 0.71% | — | Iobit Advanced System CareIobit Driver BoosterIobit Itop Screen RecorderIobit Itop Screenshot+1 | 6/7/2022 | 9/7/2026 | IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install… | |
| Modificada | Alta (7.8) | 1.1% | — | Deltaww Diascreen | 24/5/2022 | 17/6/2026 | Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow an attacker to remotely execute arbitrary code. | |
| Modificada | Alta (7.8) | 1.1% | — | Deltaww Diascreen | 24/5/2022 | 17/6/2026 | Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Media (6.5) | 0.85% | — | Stripe Smokescreen | 21/5/2022 | 17/6/2026 | Smokescreen is an HTTP proxy. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny access to additional (e.g., external)… | |
| Modificada | Alta (7) | 0.22% | — | Koyoele Remote GCKoyoele Screen Creator Advance 2Koyoele Gc-a22w-cw FirmwareKoyoele Gc-a24 Firmware+6 | 18/5/2022 | 17/6/2026 | Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, GC-A26, and GC-A26-J2), and Real time remote monitoring and control tool(Remote… | |
| Modificada | Crítica (9.8) | 1.9% | 💥 PoC | Rt-solar Solar Appscreener | 28/4/2022 | 17/6/2026 | Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document. | |
| Modificada | Media (5.3) | 0.93% | — | Stripe Smokescreen | 19/4/2022 | 17/6/2026 | Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny access… | |
| Modificada | Media (5.5) | 0.69% | — | Deltaww Cncsoft Screeneditor | 25/3/2022 | 17/6/2026 | Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may allow an attacker to disclose information. | |
| Modificada | Media (5.3) | 0.26% | — | Opensuse Cscreen | 16/3/2022 | 17/6/2026 | A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and manipulate any running cscreen seesion. This issue affects: openSUSE Factory cscreen version… |