Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 26/1/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Mobileviewpoint Wireless Multiplex Terminal Playout Server | 14/12/2020 | 17/6/2026 | The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon." | |
| Modificada | Media (5.5) | 0.45% | — | Antiy Zhijia Terminal Defense System | 3/12/2020 | 17/6/2026 | There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attacker can cause a computer crash (BSOD). | |
| Modificada | Alta (7.8) | 0.31% | — | Schneider-electric Operator Terminal Expert Runtime | 19/11/2020 | 17/6/2026 | A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert. | |
| Modificada | Alta (8.1) | 3.4% | 💥 Exploit | BT Ctroms Terminal Project BT Ctroms Terminal | 19/6/2020 | 17/6/2026 | An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to… | |
| Modificada | Crítica (9.8) | 2.3% | — | Schneider-electric Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts. | |
| Modificada | Alta (7.8) | 0.86% | — | SE Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file. | |
| Modificada | Media (5.5) | 0.88% | — | Schneider-electric Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when… | |
| Modificada | Alta (7.8) | 1.3% | — | Schneider-electric Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file. | |
| Modificada | Alta (7.8) | 1.1% | — | Schneider-electric Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file. | |
| Modificada | Crítica (9.8) | 7.9% | — | Tellabs Optical Line Terminal 1150 Firmware | 20/3/2020 | 17/6/2026 | Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020. | |
| Modificada | Alta (8.8) | 1.2% | — | Reddit Terminal Viewer Project Reddit Terminal Viewer | 14/12/2017 | 17/6/2026 | scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. | |
| Modificada | Alta (7.8) | 0.32% | — | Lxterminal Project Lxterminal | 8/5/2017 | 17/6/2026 | unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control). | |
| Modificada | Media (5.3) | 0.98% | — | Paloaltonetworks Terminal Services Agent | 20/3/2017 | 17/6/2026 | Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors. | |
| Modificada | Alta (7.8) | 0.98% | 💥 Exploit | Paloaltonetworks Terminal Services Agent | 27/1/2017 | 17/6/2026 | Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation. | |
| Modificada | Alta (7.5) | 0.91% | — | Paloaltonetworks Terminal Services Agent | 27/1/2017 | 17/6/2026 | Palo Alto Networks Terminal Services Agent before 7.0.7 allows attackers to spoof arbitrary users via unspecified vectors. | |
| Modificada | Alta (10) | 4.7% | — | Wavelink Terminal Emulation | 29/5/2015 | 17/6/2026 | Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header. | |
| Modificada | Alta (10) | 6.0% | — | Emerson DL 8000 Remote Terminal Unit FirmwareEmerson DL 8000 Remote Terminal UnitEmerson ROC 800l Remote Terminal Unit FirmwareEmerson ROC 800l Remote Terminal Unit+2 | 8/12/2014 | 16/6/2026 | Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a TCP replay attack. | |
| Modificada | Alta (7.1) | 2.0% | — | Cobham Ailor 6110 Mini-c GmdssCobham Sailor 6006 Message TerminalCobham Sailor 6222 VHFCobham Sailor 6300 MF / HF | 15/8/2014 | 17/6/2026 | Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command. NOTE: the vendor reportedly states "there is no possibility to exploit another user's credentials. | |
| Modificada | Alta (9.3) | 2.8% | — | Cobham Ailor 6110 Mini-c GmdssCobham Sailor 6006 Message TerminalCobham Sailor 6222 VHFCobham Sailor 6300 MF / HF | 15/8/2014 | 17/6/2026 | The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response. | |
| Modificada | Baja (3.5) | 1.4% | — | Omron NS Series System Program FirmwareOmron Ns10 HMI TerminalOmron Ns12 HMI TerminalOmron Ns15 HMI Terminal+2 | 24/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data. | |
| Modificada | Media (6) | 0.59% | — | Omron NS Series System Program FirmwareOmron Ns10 HMI TerminalOmron Ns12 HMI TerminalOmron Ns15 HMI Terminal+2 | 24/7/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Baja (3.5) | 2.2% | — | Gnome-terminalOpensuseOracle Solaris | 21/5/2014 | 16/6/2026 | The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demonstrated by a file containing the string "\033[100000000000000000@". | |
| Modificada | Alta (9) | 2.6% | — | Enea OSEEmerson DL 8000 Remote Terminal UnitEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the… | |
| Modificada | Alta (10) | 3.3% | — | Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson DL 8000 Remote Terminal UnitEmerson ROC 800 Remote Terminal Unit | 3/10/2013 | 16/6/2026 | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device… |