Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

159 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.30%—Teradici Graphics AgentTeradici Pcoip Standard Agent11/8/202017/6/2026
Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via forcing a crashing during the single sign-on procedure.
ModificadaMedia (6.7)0.24%—Teradici Graphics AgentTeradici Pcoip Standard Agent11/8/202017/6/2026
A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validate the signature of an external binary, which could allow an attacker to gain elevated privileges via execution in the context of the PCoIP Agent process.
ModificadaAlta (7.8)0.38%—Teradici Graphics AgentTeradici Pcoip Standard Agent11/8/202017/6/2026
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker to gain elevated privileges via execution of a malicious binary placed in the system path.
ModificadaAlta (8)0.81%—Swisscom Internet-box 2 FirmwareSwisscom Internet-box Standard FirmwareSwisscom Internet-box Plus FirmwareSwisscom Internet-box 3 Firmware+14/8/202017/6/2026
An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (user-configurable) credentials for the local Web interface or physical access to a device's plus or reset button, an…
ModificadaAlta (7.8)0.23%—Teradici Pcoip Graphics AgentTeradici Pcoip Standard Agent28/5/202017/6/2026
Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate privileges via pre-installing an application…
ModificadaAlta (7.5)2.6%—Opcfoundation Unified Architecture .net-standard22/4/202017/6/2026
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of sessions. The issue results from the lack of proper…
ModificadaAlta (7.4)1.0%—Opcfoundation Netstandard.opc.uaOpcfoundation Ua-.netstandard16/3/202017/6/2026
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.
ModificadaAlta (7.5)1.5%—Siemens DK Standard Ethernet ControllerSiemens Profinet DriverSiemens Simatic IPC SupportSiemens Ek-ertec 200 Firmware+4811/2/202017/6/2026
Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack.…
ModificadaAlta (7.8)0.66%—Teradici Pcoip Standard AgentTeradici Pcoip Graphics AgentTeradici Pcoip Client8/1/202017/6/2026
In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\Teradici\PCoIP.exe instead of the intended pcoip_vchan_printing_svc.exe file.
ModificadaMedia (6.1)0.65%—Systematicinc Iris Standards Management12/11/201917/6/2026
Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a malicious user to conduct a Cross Site Scripting attack against users of the application.
ModificadaAlta (7.5)2.1%—Siemens DK Standard Ethernet Controller FirmwareSiemens Ek-ertec 200 FirmwareSiemens Ek-ertec 200p FirmwareSiemens Simatic CFU PA Firmware+6210/10/201917/6/2026
Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.
ModificadaAlta (7.5)1.4%—Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens DK Standard Ethernet Controller FirmwareSiemens Ek-ertec 200 Firmware+3610/10/201917/6/2026
An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.
ModificadaAlta (8.1)1.4%—Facebook Zstandard25/7/201917/6/2026
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
ModificadaAlta (7)0.32%—HP Nonstop Safeguard H SeriesHP Nonstop Safeguard J SeriesHP Nonstop Safeguard L SeriesHP Nonstop Standard Security H Series+210/5/201917/6/2026
A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version SPR T9750L01^AIC or T9750H05^AIH, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND; all versions on H-series. STDSEC-STANDARD SECURITY PROD All prior versions…
ModificadaAlta (7.8)2.8%💥 PoCNema Dicom Standard2/5/201917/6/2026
An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The 128-byte preamble of a DICOM file that complies with this specification can contain arbitrary executable headers for multiple operating systems, including Portable…
ModificadaAlta (7.5)1.4%—Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens Simatic Rf185c FirmwareSiemens Simatic Cp343-1 Advanced Firmware+4917/4/201917/6/2026
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the…
ModificadaAlta (8.8)0.90%—Dell Windows Embedded Standard Wyse Device AgentDell Wyse Thinlinux Hagent7/3/201917/6/2026
Dell WES Wyse Device Agent versions prior to 14.1.2.9 and Dell Wyse ThinLinux HAgent versions prior to 5.4.55 00.10 contain a buffer overflow vulnerability. An unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code on the system with privileges of the FTP client by sending…
ModificadaAlta (7.5)0.70%—Swisscom Internet-box Standard FirmwareSwisscom Internet-box Light FirmwareSwisscom Internet-box Plus FirmwareSwisscom Internet-box 2 Firmware17/12/201817/6/2026
A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, and Plus) prior to v09.04.00 and Internet-Box light prior to v08.05.02 allows remote code execution. No authentication is required to exploit this vulnerability. Sending a simple UDP packet to port…
ModificadaMedia (5.3)0.29%—Opcfoundation Ua-.net-legacyOpcfoundation Ua-.netstandard3/10/201817/6/2026
Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.
ModificadaAlta (7.5)12%💥 PoCOpcfoundation Unified Architecture-.net-legacyOpcfoundation Unified Architecture-javaOpcfoundation Unified Architecture .net-standardOpcfoundation Unified Architecture Ansic+114/9/201817/6/2026
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
ModificadaMedia (5.3)1.2%—Opcfoundation Ua-.net-legacyOpcfoundation Ua-.netstandard13/6/201817/6/2026
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed…
ModificadaMedia (5.4)0.76%—Sulu-standard9/1/201817/6/2026
Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.
ModificadaAlta (8.7)3.3%—Siemens Simatic S7-200 FirmwareSiemens Simatic S7-400pn V6 FirmwareSiemens Simatic S7-400h V6 FirmwareSiemens Simatic S7-400pn/dp V7 Firmware+3426/12/201717/6/2026
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
ModificadaCrítica (9.1)2.3%—Qualitysoft QND Advance/standard1/12/201717/6/2026
Directory traversal vulnerability in QND Advance/Standard allows an attacker to read arbitrary files via a specially crafted command.
ModificadaAlta (7.1)0.91%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+7511/5/201717/6/2026
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
Orbitaley — Vulnerabilidades