Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)4.9%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+314/1/202117/6/2026
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a…
ModificadaCrítica (9.8)10%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+314/1/202117/6/2026
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a…
ModificadaCrítica (9.1)4.9%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+314/1/202117/6/2026
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a…
ModificadaAlta (7.8)0.58%💥 PoCWftpserver Wing FTP Server7/3/202017/6/2026
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session cookies within the Wing FTP HTTP interface and administration panel. These…
ModificadaAlta (7.8)0.81%💥 PoCWftpserver Wing FTP Server7/3/202017/6/2026
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files.
ModificadaAlta (7.8)0.43%—Wftpserver Wing FTP Server7/3/202017/6/2026
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to…
ModificadaCrítica (9.8)4.0%💥 PoCOpservices Opmon6/2/202017/6/2026
An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .
ModificadaAlta (7.8)0.38%—Opservices Opmon6/2/202017/6/2026
An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudoers file, which by default allows the execution of programs (e.g. nmap) without the need for a password with sudo.
ModificadaAlta (7.5)1.2%—Opservices Opmon6/2/202017/6/2026
An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option.
ModificadaAlta (8.1)2.4%—Gatewaygeomatics Mapserver9/1/202016/6/2026
Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.
ModificadaCrítica (9.8)1.2%—Opservices Opmon7/1/202017/6/2026
An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.
ModificadaAlta (7.5)2.2%—Osgeo Mapserver29/10/201916/6/2026
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
ModificadaAlta (8.8)0.72%—Wpserveur WPS Hide Login22/10/201917/6/2026
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
ModificadaMedia (5.3)1.6%—Statichttpserver Project Statichttpserver3/9/201917/6/2026
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
ModificadaCrítica (9.8)3.0%—Wpserveur WPS Hide Login30/8/201917/6/2026
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
ModificadaCrítica (9.8)3.0%—Wpserveur WPS Hide Login30/8/201917/6/2026
The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.
ModificadaCrítica (9.8)3.0%—Wpserveur WPS Hide Login30/8/201917/6/2026
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
ModificadaCrítica (9.8)8.6%💥 ExploitWpserveur WPS Hide Login30/8/201917/6/2026
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
ModificadaCrítica (9.8)3.4%—Wpserveur WPS Child Theme Generator30/8/201917/6/2026
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
ModificadaCrítica (9.8)7.7%—Axentra Hipserv19/6/201917/6/2026
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of the affected device.
ModificadaMedia (6.5)0.44%—Wampserver10/6/201917/6/2026
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.
ModificadaMedia (6.1)0.65%—Wampserver20/12/201817/6/2026
Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in very low. This attack appear to be exploitable via payload onmouseover. This vulnerability appears to have been fixed in 3.1.5 and later.
ModificadaMedia (6.5)0.61%—Phpservermonitor PHP Server Monitor18/12/201817/6/2026
PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action.
ModificadaMedia (5.3)1.3%—Simplehttpserver Project Simplehttpserver4/12/201817/6/2026
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.
ModificadaAlta (7.5)2.0%—Simplehttpserver Project Simplehttpserver31/8/201817/6/2026
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
Orbitaley — Vulnerabilidades