Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | |
| Modificada | Alta (8.8) | 1.6% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | |
| Modificada | Alta (8.8) | 1.5% | — | Sciencelogic SL1 | 9/8/2023 | 17/6/2026 | A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | |
| Modificada | Media (4.8) | 0.40% | — | Agilelogix Store Locator | 22/6/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 versions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Onelogin Ruby-saml | 27/5/2023 | 17/6/2026 | xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. | |
| Modificada | Alta (8.8) | 53% | 💥 Exploit | Realtimelogic Fuguhub | 17/2/2023 | 17/6/2026 | Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. | |
| Modificada | Media (5.4) | 0.47% | — | Agilelogix Store Locator | 23/1/2023 | 17/6/2026 | The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Media (6.1) | 0.25% | — | Agilelogix Store Locator | 18/11/2022 | 17/6/2026 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress. | |
| Modificada | Alta (8.8) | 70% | 💥 Exploit | Schneider-electric Spacelogic C-bus Home Controller Firmware | 13/7/2022 | 17/6/2026 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460… | |
| Modificada | Crítica (9.8) | 5.2% | — | Rockwellautomation Compactlogix 1768-l43 FirmwareRockwellautomation Compactlogix 1768-l45 FirmwareRockwellautomation Compactlogix 1769-l31 FirmwareRockwellautomation Compactlogix 1769-l32c Firmware+20 | 11/4/2022 | 17/6/2026 | An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the… | |
| Modificada | Alta (7.8) | 0.50% | — | Realtimelogic Barracudadrive | 4/9/2020 | 17/6/2026 | Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem. | |
| Modificada | Media (6.5) | 5.9% | — | Elog Project ElogFedoraproject Fedora | 17/12/2019 | 17/6/2026 | ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests. | |
| Modificada | Alta (7.5) | 29% | — | Elog Project ElogFedoraproject Fedora | 17/12/2019 | 17/6/2026 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request. | |
| Modificada | Alta (7.5) | 2.9% | — | Elog Project ElogFedoraproject Fedora | 17/12/2019 | 17/6/2026 | ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the ELOG function retrieve_url() to use a freed variable. | |
| Modificada | Alta (7.5) | 46% | — | Elog Project ElogFedoraproject Fedora | 17/12/2019 | 17/6/2026 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP POST request. | |
| Modificada | Alta (7.5) | 1.3% | — | Elog Project ElogFedoraproject Fedora | 17/12/2019 | 17/6/2026 | ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames and, in older versions of ELOG,… | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins GIT Changelog | 25/9/2019 | 17/6/2026 | Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Alta (7.5) | 1.7% | — | Onelogin Saml SSO | 22/8/2019 | 17/6/2026 | The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 7Microsoft Windows Server 2008Siemens Axiom Multix M FirmwareSiemens Axiom Vertix MD Trauma Firmware+63 | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | |
| Modificada | Crítica (9.8) | 2.5% | — | Onelogin Ruby-saml | 17/4/2019 | 17/6/2026 | OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service… | |
| Modificada | Crítica (9.8) | 4.7% | 💥 PoC | Onelogin Pythonsaml | 17/4/2019 | 17/6/2026 | OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service… | |
| Modificada | Media (6.1) | 0.99% | — | Jenkins GIT Changelog | 9/1/2019 | 17/6/2026 | A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the… | |
| Modificada | Alta (7.5) | 1.0% | — | Fedoraproject FedoraElog Project Elog | 27/6/2017 | 17/6/2026 | elog 3.1.1 allows remote attackers to post data as any username in the logbook. | |
| Modificada | Alta (7.5) | 1.2% | — | Onelogin Ruby-saml | 23/1/2017 | 17/6/2026 | Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. | |
| Modificada | Crítica (9.8) | 5.2% | — | BMC Bladelogic Server Automation Console | 13/12/2016 | 17/6/2026 | BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process. |