Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.31%—Intel Unite12/11/202017/6/2026
Improper buffer restrictions in the Intel(R) Unite Client for Windows* before version 4.2.13064 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.1)0.83%—Unitedplanet Intrexx14/10/202017/6/2026
Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to inject arbitrary web script or HTML via the request parameter.
ModificadaCrítica (9.8)1.5%—Siemens Simatic HMI United Comfort Panels Firmware9/9/202017/6/2026
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a set number of characters versus the whole provided string. This could allow a remote attacker to…
ModificadaCrítica (9.8)1.5%—Siemens Simatic HMI Basic Panels 2ND Generation FirmwareSiemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Mobile Panels FirmwareSiemens Simatic HMI United Comfort Panels Firmware9/9/202017/6/2026
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected…
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaCrítica (9.8)4.0%—Unitedplanet Intrexx31/1/202017/6/2026
Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.
ModificadaMedia (6.1)0.92%—United-security-providers Secure Entry Server28/1/202016/6/2026
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
ModificadaMedia (6.5)1.0%—Unitegallery Unite Gallery Lite26/9/201917/6/2026
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
ModificadaAlta (8.8)2.4%—Unitegallery Unite Gallery Lite26/9/201917/6/2026
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
ModificadaAlta (8.8)1.1%—Unitegallery Unite Gallery Lite26/9/201917/6/2026
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
ModificadaMedia (6.1)0.91%—Joomunited WP Latest Posts20/8/201917/6/2026
The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
ModificadaAlta (8.3)1.7%—Polycom Unified Communications SoftwarePolycom United Communications Software29/7/201917/6/2026
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.
ModificadaCrítica (9.8)2.3%—Intel Unite17/5/201917/6/2026
A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privilege via network access.
ModificadaAlta (7.5)2.0%—Intel Unite17/5/201917/6/2026
Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially cause a denial of service via network access.
ModificadaCrítica (9.8)1.8%—Intel Unite18/2/201917/6/2026
Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalation of privilege to the Intel Unite(R) Solution administrative portal via network access.
ModificadaCrítica (9.1)1.5%—Intel Unite16/11/201717/6/2026
Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or information disclosure.
ModificadaMedia (4.3)1.9%—Unitedplanet Intrexx19/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.
ModificadaMedia (5.4)0.27%—Unitedhawknation United Hawk Nation21/10/201417/6/2026
The United Hawk Nation (aka com.united12thman) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Roguewaveproductionsllc Wild Women United16/10/201417/6/2026
The Wild Women United (aka com.wildwomenunited) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Uanw United Advantage NW Federal CR29/9/201417/6/2026
The United Advantage NW Federal Cr (aka com.myappengine.uanwfcu) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Unitedecu United Educational CU29/9/201417/6/2026
The United Educational CU (aka com.metova.cuae.uecu) application 1.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Uhcu United Heritage Mobile28/9/201417/6/2026
The United Heritage Mobile (aka Fi_Mobile.UHCU) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (9.3)4.9%—Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite21/1/200916/6/2026
The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to…
ModificadaAlta (9.3)5.5%—Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite20/1/200916/6/2026
Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via…
ModificadaAlta (9.3)6.9%—Blackberry Enterprise ServerBlackberry UniteRIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server FOR Domino+321/7/200816/6/2026
Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment.
Orbitaley — Vulnerabilidades