Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.6%—Sciencelogic SL19/8/202317/6/2026
A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
ModificadaAlta (8.8)1.6%—Sciencelogic SL19/8/202317/6/2026
A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
ModificadaAlta (8.8)1.5%—Sciencelogic SL19/8/202317/6/2026
A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
ModificadaMedia (4.8)0.40%—Agilelogix Store Locator22/6/202317/6/2026
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 versions.
ModificadaCrítica (9.8)1.3%—Onelogin Ruby-saml27/5/202317/6/2026
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
ModificadaAlta (8.8)53%💥 ExploitRealtimelogic Fuguhub17/2/202317/6/2026
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.
ModificadaMedia (5.4)0.47%—Agilelogix Store Locator23/1/202317/6/2026
The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
ModificadaMedia (6.1)0.25%—Agilelogix Store Locator18/11/202217/6/2026
Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress.
ModificadaAlta (8.8)70%💥 ExploitSchneider-electric Spacelogic C-bus Home Controller Firmware13/7/202217/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460…
ModificadaCrítica (9.8)5.2%—Rockwellautomation Compactlogix 1768-l43 FirmwareRockwellautomation Compactlogix 1768-l45 FirmwareRockwellautomation Compactlogix 1769-l31 FirmwareRockwellautomation Compactlogix 1769-l32c Firmware+2011/4/202217/6/2026
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the…
ModificadaAlta (7.8)0.50%—Realtimelogic Barracudadrive4/9/202017/6/2026
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.
ModificadaMedia (6.5)5.9%—Elog Project ElogFedoraproject Fedora17/12/201917/6/2026
ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.
ModificadaAlta (7.5)29%—Elog Project ElogFedoraproject Fedora17/12/201917/6/2026
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request.
ModificadaAlta (7.5)2.9%—Elog Project ElogFedoraproject Fedora17/12/201917/6/2026
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the ELOG function retrieve_url() to use a freed variable.
ModificadaAlta (7.5)46%—Elog Project ElogFedoraproject Fedora17/12/201917/6/2026
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP POST request.
ModificadaAlta (7.5)1.3%—Elog Project ElogFedoraproject Fedora17/12/201917/6/2026
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames and, in older versions of ELOG,…
ModificadaMedia (6.5)1.0%—Jenkins GIT Changelog25/9/201917/6/2026
Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
ModificadaAlta (7.5)1.7%—Onelogin Saml SSO22/8/201917/6/2026
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Windows 7Microsoft Windows Server 2008Siemens Axiom Multix M FirmwareSiemens Axiom Vertix MD Trauma Firmware+6316/5/201917/6/2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
ModificadaCrítica (9.8)2.5%—Onelogin Ruby-saml17/4/201917/6/2026
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service…
ModificadaCrítica (9.8)4.7%💥 PoCOnelogin Pythonsaml17/4/201917/6/2026
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service…
ModificadaMedia (6.1)0.99%—Jenkins GIT Changelog9/1/201917/6/2026
A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the…
ModificadaAlta (7.5)1.0%—Fedoraproject FedoraElog Project Elog27/6/201717/6/2026
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
ModificadaAlta (7.5)1.2%—Onelogin Ruby-saml23/1/201717/6/2026
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
ModificadaCrítica (9.8)5.2%—BMC Bladelogic Server Automation Console13/12/201617/6/2026
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.
Orbitaley — Vulnerabilidades