Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | SAP Landscape TransformationSAP Landscape Transformation Replication ServerSAP S/4hanaSAP Test Data Migration Server | 14/9/2021 | 17/6/2026 | Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise… | |
| Modificada | Alta (7.8) | 1.00% | — | Hornerautomation Cscape | 25/8/2021 | 17/6/2026 | Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write via an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 1.00% | — | Hornerautomation Cscape | 25/8/2021 | 17/6/2026 | Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.97% | — | Hornerautomation Cscape | 25/8/2021 | 17/6/2026 | Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.22% | — | Hornerautomation Cscape | 23/4/2021 | 17/6/2026 | Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permissions, including read/write access. This may allow unprivileged users to modify the binaries and configuration files and lead to local privilege escalation. | |
| Modificada | Alta (7.8) | 1.0% | — | Hornerautomation Cscape | 23/4/2021 | 17/6/2026 | Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory corruption. An attacker could leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.58% | — | Shescape Project Shescape | 19/3/2021 | 17/6/2026 | shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an example see the referenced GitHub Security Advisory. The… | |
| Modificada | Alta (7.8) | 1.3% | — | Hornerautomation CscapeSiemens Cscape | 9/2/2021 | 17/6/2026 | Cscape (All versions prior to 9.90 SP3.5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process. | |
| Modificada | Alta (7.2) | 1.2% | — | SAP Adaptive ExtensionsSAP Landscape Management | 14/4/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context,… | |
| Modificada | Alta (7.8) | 0.43% | — | Redsoftware Pdfescape | 5/3/2020 | 17/6/2026 | An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attacker to gain privileges and execute code via DLL hijacking. | |
| Modificada | Alta (7.5) | 1.9% | — | Atos Unify Openscape UC WEB Client | 21/2/2020 | 17/6/2026 | Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and… | |
| Modificada | Media (6.1) | 0.65% | — | Atos Unify Openscape UC WEB Client | 21/2/2020 | 17/6/2026 | Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload. | |
| Modificada | Alta (7.2) | 1.7% | — | SAP Landscape Management | 12/2/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management. | |
| Modificada | Alta (7.2) | 1.6% | — | SAP Landscape Management | 12/2/2020 | 17/6/2026 | SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation. | |
| Modificada | Crítica (10) | 2.2% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain… | |
| Modificada | Crítica (9.9) | 1.1% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+5 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software… | |
| Modificada | Alta (8.6) | 1.4% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices… | |
| Modificada | Crítica (10) | 2.7% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Crítica (10) | 4.9% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+5 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X,… | |
| Modificada | Crítica (10) | 1.6% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to… | |
| Modificada | Crítica (9.8) | 1.7% | — | Atos Openstage 80 FirmwareAtos Openstage 80 G FirmwareAtos Openstage 60 G FirmwareAtos Openstage 60 Firmware+10 | 9/1/2020 | 17/6/2026 | Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface | |
| Modificada | Crítica (9.8) | 2.6% | — | Atos Openstage 80 FirmwareAtos Openstage 80 G FirmwareAtos Openstage 60 G FirmwareAtos Openstage 60 Firmware+11 | 9/1/2020 | 17/6/2026 | Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface | |
| Modificada | Alta (7.8) | 1.9% | — | Hornerautomation Cscape | 18/10/2019 | 17/6/2026 | In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.9% | — | Hornerautomation Cscape | 18/10/2019 | 17/6/2026 | In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access information and remotely execute arbitrary code. | |
| Modificada | Media (4.9) | 0.88% | — | SAP Landscape Management | 8/10/2019 | 17/6/2026 | Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure. |