Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.28% | — | Intel Solid-state Drive Toolbox | 17/2/2021 | 17/6/2026 | Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.1) | 4.9% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+3 | 14/1/2021 | 17/6/2026 | KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a… | |
| Modificada | Crítica (9.8) | 10% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+3 | 14/1/2021 | 17/6/2026 | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a… | |
| Modificada | Crítica (9.1) | 4.9% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+3 | 14/1/2021 | 17/6/2026 | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a… | |
| Modificada | Crítica (9.8) | 4.6% | — | Jetbrains Toolbox | 16/11/2020 | 17/6/2026 | JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler. | |
| Modificada | Alta (7.5) | 1.4% | — | Jetbrains Toolbox | 16/11/2020 | 17/6/2026 | JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler. | |
| Modificada | Alta (7.5) | 0.69% | — | Jetbrains Toolbox | 8/8/2020 | 17/6/2026 | In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file. | |
| Modificada | Alta (7.5) | 1.3% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier,… | |
| Modificada | Alta (7.5) | 1.4% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric EM ConfiguratorMitsubishielectric GT Designer3+16 | 30/6/2020 | 17/6/2026 | Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, EM Software Development Kit (EM Configurator) Ver. 1.010L and earlier, GT Designer3 (GOT2000) Ver. 1.221F and earlier, GX LogViewer Ver. 1.96A and earlier, GX Works2 Ver.… | |
| Modificada | Alta (7.3) | 1.0% | — | Jetbrains Toolbox | 31/10/2019 | 17/6/2026 | In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. | |
| Modificada | Media (4.7) | 0.47% | — | Microchip Atmel ToolboxAthena-scs IdprotectCryptsoft S/A Idflex VTecsec Armored Card+1 | 3/10/2019 | 17/6/2026 | Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue… | |
| Modificada | Media (5.9) | 0.66% | — | Jetbrains Toolbox | 2/10/2019 | 17/6/2026 | JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection. | |
| Modificada | Alta (7.8) | 2.2% | — | Pc-doctor ToolboxDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 25/6/2019 | 17/6/2026 | PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element. | |
| Modificada | Media (6.1) | 0.84% | — | NIH Ncbi Toolbox | 2/5/2019 | 17/6/2026 | An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument. | |
| Modificada | Crítica (9.8) | 1.6% | — | NIH Ncbi Toolbox | 2/5/2019 | 17/6/2026 | A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox. | |
| Modificada | Crítica (9.1) | 8.6% | 💥 Exploit | NIH Ncbi Toolbox | 2/5/2019 | 17/6/2026 | A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string. | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Solid State Drive Toolbox | 14/12/2018 | 17/6/2026 | Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 5.6% | — | Crestron Toolbox Protocol Firmware | 8/6/2018 | 17/6/2026 | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protocol (CTP). | |
| Modificada | Crítica (9.8) | 7.5% | — | Crestron Toolbox Protocol Firmware | 8/6/2018 | 17/6/2026 | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP). | |
| Modificada | Media (6.7) | 0.40% | — | Intel Solid State Drive Toolbox | 31/5/2017 | 17/6/2026 | There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.33% | — | Intel Solid-state Drive Toolbox | 10/10/2016 | 17/6/2026 | The updater subsystem in Intel SSD Toolbox before 3.3.7 allows local users to gain privileges via unspecified vectors. | |
| Modificada | Alta (7.1) | 1.3% | — | Softwaretoolbox TOP Server | 28/8/2013 | 16/6/2026 | The DNP Master Driver in Software Toolbox TOP Server before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input… | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Freesoftwaretoolbox Batch Audio Converter | 21/6/2010 | 16/6/2026 | Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Arnos Toolbox Wp-downloadWordpress WP Download | 2/4/2008 | 16/6/2026 | SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter. | |
| Modificada | Media (5) | 1.4% | — | Radio Toolbox Steamcast | 1/2/2008 | 16/6/2026 | Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via a long Ogg tag. |