Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.31% | — | Intel Unite | 12/11/2020 | 17/6/2026 | Improper buffer restrictions in the Intel(R) Unite Client for Windows* before version 4.2.13064 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.1) | 0.83% | — | Unitedplanet Intrexx | 14/10/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to inject arbitrary web script or HTML via the request parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Siemens Simatic HMI United Comfort Panels Firmware | 9/9/2020 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a set number of characters versus the whole provided string. This could allow a remote attacker to… | |
| Modificada | Crítica (9.8) | 1.5% | — | Siemens Simatic HMI Basic Panels 2ND Generation FirmwareSiemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Mobile Panels FirmwareSiemens Simatic HMI United Comfort Panels Firmware | 9/9/2020 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected… | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Crítica (9.8) | 4.0% | — | Unitedplanet Intrexx | 31/1/2020 | 17/6/2026 | Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors. | |
| Modificada | Media (6.1) | 0.92% | — | United-security-providers Secure Entry Server | 28/1/2020 | 16/6/2026 | Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default. | |
| Modificada | Media (6.5) | 1.0% | — | Unitegallery Unite Gallery Lite | 26/9/2019 | 17/6/2026 | The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters. | |
| Modificada | Alta (8.8) | 2.4% | — | Unitegallery Unite Gallery Lite | 26/9/2019 | 17/6/2026 | The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php. | |
| Modificada | Alta (8.8) | 1.1% | — | Unitegallery Unite Gallery Lite | 26/9/2019 | 17/6/2026 | The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation. | |
| Modificada | Media (6.1) | 0.91% | — | Joomunited WP Latest Posts | 20/8/2019 | 17/6/2026 | The wp-latest-posts plugin before 3.7.5 for WordPress has XSS. | |
| Modificada | Alta (8.3) | 1.7% | — | Polycom Unified Communications SoftwarePolycom United Communications Software | 29/7/2019 | 17/6/2026 | A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.3% | — | Intel Unite | 17/5/2019 | 17/6/2026 | A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (7.5) | 2.0% | — | Intel Unite | 17/5/2019 | 17/6/2026 | Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially cause a denial of service via network access. | |
| Modificada | Crítica (9.8) | 1.8% | — | Intel Unite | 18/2/2019 | 17/6/2026 | Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalation of privilege to the Intel Unite(R) Solution administrative portal via network access. | |
| Modificada | Crítica (9.1) | 1.5% | — | Intel Unite | 16/11/2017 | 17/6/2026 | Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or information disclosure. | |
| Modificada | Media (4.3) | 1.9% | — | Unitedplanet Intrexx | 19/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Unitedhawknation United Hawk Nation | 21/10/2014 | 17/6/2026 | The United Hawk Nation (aka com.united12thman) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Roguewaveproductionsllc Wild Women United | 16/10/2014 | 17/6/2026 | The Wild Women United (aka com.wildwomenunited) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Uanw United Advantage NW Federal CR | 29/9/2014 | 17/6/2026 | The United Advantage NW Federal Cr (aka com.myappengine.uanwfcu) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Unitedecu United Educational CU | 29/9/2014 | 17/6/2026 | The United Educational CU (aka com.metova.cuae.uecu) application 1.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Uhcu United Heritage Mobile | 28/9/2014 | 17/6/2026 | The United Heritage Mobile (aka Fi_Mobile.UHCU) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 4.9% | — | Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite | 21/1/2009 | 16/6/2026 | The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to… | |
| Modificada | Alta (9.3) | 5.5% | — | Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite | 20/1/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via… | |
| Modificada | Alta (9.3) | 6.9% | — | Blackberry Enterprise ServerBlackberry UniteRIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server FOR Domino+3 | 21/7/2008 | 16/6/2026 | Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment. |