Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

3716 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.90%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and…
ModificadaCrítica (9.8)1.4%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.
ModificadaCrítica (9.8)34%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.
ModificadaCrítica (9.8)1.2%—Vmware Vcenter Server22/6/202317/6/2026
The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.
ModificadaCrítica (9.8)1.8%—Vmware Vcenter Server22/6/202317/6/2026
The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts…
ModificadaMedia (4.8)0.45%—Gbcom LAC WEB Control Center22/6/202317/6/2026
Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device.
ModificadaMedia (6.1)0.39%—Subnet Powersystem Center19/6/202317/6/2026
SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications.
ModificadaCrítica (9.1)0.58%—Subnet Powersystem Center19/6/202317/6/2026
SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-of-service condition or a loss of data integrity.
ModificadaAlta (7.8)0.22%—Siemens Jt2goSiemens Teamcenter Visualization13/6/202317/6/2026
A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),…
ModificadaAlta (7.8)0.22%—Siemens Jt2goSiemens Teamcenter Visualization13/6/202317/6/2026
A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),…
ModificadaMedia (5.5)0.19%—Siemens Jt2goSiemens Teamcenter Visualization13/6/202317/6/2026
A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),…
ModificadaMedia (5.5)0.18%—Siemens Jt2goSiemens Teamcenter Visualization13/6/202317/6/2026
A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),…
ModificadaMedia (5.3)0.62%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie FirmwarePhoenixcontact FL Mguard 4302 Firmware+2213/6/202317/6/2026
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
ModificadaAlta (7.8)0.26%—Siemens Jt2goSiemens Teamcenter Visualization7/6/202317/6/2026
Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process.
ModificadaAlta (7.5)0.46%—Asustor Download Center31/5/202317/6/2026
Download Center no valida correctamente la ruta de archivo enviada por un usuario. Un atacante puede aprovechar esta vulnerabilidad para obtener acceso no autorizado a archivos o directorios confidenciales sin las restricciones de permisos adecuadas. Download Center se ve afectado en ADM 4.0 y en versiones superiores.…
ModificadaMedia (6.1)0.47%—Broadcom Vmware Nsx-t Data Center26/5/202317/6/2026
NSX-T contiene una vulnerabilidad de cross-site scripting reflejado debido a la falta de validación de entrada. Un atacante remoto puede inyectar HTML o JavaScript para redirigir a páginas maliciosas.
ModificadaAlta (7.1)0.30%—Opentext Archive Center Administration24/5/202317/6/2026
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft…
ModificadaMedia (6.1)0.38%—Hitachi OPS Center Analyzer23/5/202317/6/2026
Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) allows Reflected XSS.This issue affects Hitachi Ops Center Analyzer: from 10.9.1-00 before 10.9.2-00.
ModificadaMedia (4.3)0.48%—Cisco Catalyst Center18/5/202317/6/2026
Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas…
ModificadaMedia (4.3)0.49%—Cisco Catalyst Center18/5/202317/6/2026
Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas…
ModificadaAlta (8.8)0.62%—Cisco Catalyst Center18/5/202317/6/2026
Varias vulnerabilidades en la API del software Cisco DNA Center podrían permitir que un atacante remoto autenticado lea información de un contenedor restringido, enumere información de usuario o ejecute comandos arbitrarios en un contenedor restringido como usuario root. Para obtener más información sobre estas…
ModificadaCrítica (9.8)0.88%—Oretnom23 Student Study Center Desk Management System18/5/202317/6/2026
Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.
ModificadaCrítica (9.8)0.96%—Netapp Snapcenter12/5/202317/6/2026
SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user.
ModificadaAlta (7.8)0.20%—Intel Data Center Manager10/5/202317/6/2026
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.55%—Intel Data Center Manager10/5/202317/6/2026
Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.