Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.49%💥 ExploitNetop Remote Control ClientAI13/8/202516/6/2026
NetOp (now part of Impero Software) Remote Control Client v9.5 is vulnerable to a stack-based buffer overflow when processing .dws configuration files. If a .dws file contains a string longer than 520 bytes, the application fails to perform proper bounds checking, allowing an attacker to execute arbitrary code when…
AnalizadaAlta (7.5)0.81%💥 PoCMicrosoft Dynamics 365 GuidesMicrosoft Dynamics 365 Remote AssistMicrosoft TeamsMicrosoft Teams Panels+112/8/202517/6/2026
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
AplazadaMedia (6.9)0.37%—Thinbus Javascript Secure Remote PasswordAI7/8/202517/6/2026
Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. In versions 2.0.0 and below, a protocol compliance bug causes the client to generate a fixed 252 bits of entropy instead of the intended bit length of the safe prime (defaulted to 2048 bits). The…
AnalizadaMedia (5.4)0.46%—Checkpoint Mobile AccessCheckpoint Remote Access VPN6/8/202517/6/2026
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
AplazadaMedia (4.8)0.08%—Tsplus Remote AccessAI29/7/202517/6/2026
Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's hash is stored in a system registry accessible to regular users, making it possible to perform a brute-force attack using rainbow tables,…
AplazadaAlta (8.2)0.20%—HCL Bigfix Remote Control ServerAI29/7/202517/6/2026
Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages.
AplazadaCrítica (9.3)2.3%💥 ExploitDG Remote Control ServerAI23/7/202517/6/2026
Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the default configuration. The server exposes a custom UDP-based control protocol that accepts remote keyboard input events without verification. An attacker on the same…
AplazadaAlta (7.1)0.14%—Atakanau Import CDN Remote ImagesAI16/7/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images import-cdn-remote-images allows Stored XSS.This issue affects Import CDN-Remote Images: from n/a through <= 2.1.2.
AplazadaCrítica (9.6)78%💥 PoCMcp-remoteAI9/7/202517/6/2026
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response URL
AnalizadaAlta (8.8)1.0%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+138/7/202517/6/2026
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AplazadaCrítica (9.3)2.3%💥 ExploitAexol Studio Remote FOR MACAI3/7/202517/6/2026
An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in versions up to and including 2025.7. When the application is configured with authentication disabled (i.e., the "Allow unknown devices" option is enabled), the…
AnalizadaCrítica (9.8)0.76%—HPE Insight Remote Support1/7/202517/6/2026
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
AnalizadaAlta (7.5)46%—HPE Insight Remote Support1/7/202517/6/2026
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
AnalizadaAlta (7.5)0.54%—HPE Insight Remote Support1/7/202517/6/2026
A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service
AplazadaAlta (7)0.17%—Teamviewer RemoteAITeamviewer TensorAI24/6/202517/6/2026
Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a local unprivileged user to trigger arbitrary file deletion with SYSTEM privileges via leveraging the MSI rollback mechanism. The vulnerability only…
AnalizadaAlta (8.6)0.95%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support16/6/202517/6/2026
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
AnalizadaMedia (6.5)1.4%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1310/6/202517/6/2026
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
AplazadaAlta (7.8)0.23%—Solarwinds Dameware Mini Remote ControlAI2/6/202517/6/2026
The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability.
AnalizadaAlta (7.5)0.57%—Devolutions Remote Desktop Manager29/5/202517/6/2026
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared…
AplazadaAlta (7.2)0.45%—Teltonika-networks Remote Management SystemAI29/5/202517/6/2026
In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge. The victims account and their company can…
AplazadaAlta (7.4)0.82%—Gnome-remote-desktopAI22/5/202530/6/2026
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files…
AplazadaAlta (7.1)0.22%—Andreyk Remote Images GrabberAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andreyk Remote Images Grabber remote-images-grabber allows Reflected XSS.This issue affects Remote Images Grabber: from n/a through <= 0.6.
AnalizadaAlta (8.8)1.4%—Microsoft Remote DesktopMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1313/5/202517/6/2026
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.7)0.62%—Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+113/5/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All…
AnalizadaAlta (8.7)0.62%—Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+113/5/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All…
Orbitaley — Vulnerabilidades