Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.3%—SAP Landscape TransformationSAP Landscape Transformation Replication ServerSAP S/4hanaSAP Test Data Migration Server14/9/202117/6/2026
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise…
ModificadaAlta (7.8)1.00%—Hornerautomation Cscape25/8/202117/6/2026
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write via an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)1.00%—Hornerautomation Cscape25/8/202117/6/2026
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.97%—Hornerautomation Cscape25/8/202117/6/2026
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.22%—Hornerautomation Cscape23/4/202117/6/2026
Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write access. This may allow unprivileged users to modify the binaries and configuration files and lead to local privilege escalation.
ModificadaAlta (7.8)1.0%—Hornerautomation Cscape23/4/202117/6/2026
Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory corruption. An attacker could leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.8)0.58%—Shescape Project Shescape19/3/202117/6/2026
shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an example see the referenced GitHub Security Advisory. The…
ModificadaAlta (7.8)1.3%—Hornerautomation CscapeSiemens Cscape9/2/202117/6/2026
Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.
ModificadaAlta (7.2)1.2%—SAP Adaptive ExtensionsSAP Landscape Management14/4/202017/6/2026
SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context,…
ModificadaAlta (7.8)0.43%—Redsoftware Pdfescape5/3/202017/6/2026
An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attacker to gain privileges and execute code via DLL hijacking.
ModificadaAlta (7.5)1.9%—Atos Unify Openscape UC WEB Client21/2/202017/6/2026
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and…
ModificadaMedia (6.1)0.65%—Atos Unify Openscape UC WEB Client21/2/202017/6/2026
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload.
ModificadaAlta (7.2)1.7%—SAP Landscape Management12/2/202017/6/2026
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.
ModificadaAlta (7.2)1.6%—SAP Landscape Management12/2/202017/6/2026
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation.
ModificadaCrítica (10)2.2%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+224/1/202017/6/2026
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain…
ModificadaCrítica (9.9)1.1%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+524/1/202017/6/2026
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software…
ModificadaAlta (8.6)1.4%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+224/1/202017/6/2026
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices…
ModificadaCrítica (10)2.7%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+224/1/202017/6/2026
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.
ModificadaCrítica (10)4.9%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+524/1/202017/6/2026
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X,…
ModificadaCrítica (10)1.6%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+224/1/202017/6/2026
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to…
ModificadaCrítica (9.8)1.7%—Atos Openstage 80 FirmwareAtos Openstage 80 G FirmwareAtos Openstage 60 G FirmwareAtos Openstage 60 Firmware+109/1/202017/6/2026
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
ModificadaCrítica (9.8)2.6%—Atos Openstage 80 FirmwareAtos Openstage 80 G FirmwareAtos Openstage 60 G FirmwareAtos Openstage 60 Firmware+119/1/202017/6/2026
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
ModificadaAlta (7.8)1.9%—Hornerautomation Cscape18/10/201917/6/2026
In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution.
ModificadaAlta (7.8)1.9%—Hornerautomation Cscape18/10/201917/6/2026
In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access information and remotely execute arbitrary code.
ModificadaMedia (4.9)0.88%—SAP Landscape Management8/10/201917/6/2026
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.