Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.65% | — | Baptiste Gourdin TalkbackAI | 11/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.36% | — | MirotalkAI | 11/10/2024 | 17/6/2026 | Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server. | |
| Aplazada | Media (4.7) | 0.44% | — | MirotalkAI | 11/10/2024 | 17/6/2026 | Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary code via sending crafted payloads in messages to other users over RTC connections. | |
| Aplazada | Crítica (9.1) | 0.43% | — | MirotalkAI | 11/10/2024 | 17/6/2026 | Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name. | |
| Aplazada | Alta (7.5) | 0.68% | — | MirotalkAI | 11/10/2024 | 17/6/2026 | Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting. | |
| Aplazada | Media (6.4) | 0.34% | — | Rumbletalk Live Group ChatAI | 1/10/2024 | 17/6/2026 | The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rumbletalk-admin-button' shortcode in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Crítica (9.2) | 0.54% | — | Rockwellautomation Factorytalk Batch View | 12/9/2024 | 17/6/2026 | CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication. | |
| Analizada | Crítica (9.2) | 1.3% | — | Rockwellautomation Factorytalk View | 12/9/2024 | 17/6/2026 | CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this… | |
| Analizada | Alta (8.5) | 1.7% | — | Rockwellautomation Factorytalk View | 14/8/2024 | 17/6/2026 | CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions. | |
| Modificada | Baja (1.8) | 0.18% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 16/7/2024 | 17/6/2026 | An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are… | |
| Modificada | Media (6) | 0.30% | — | Rockwellautomation Factorytalk Policy Manager | 16/7/2024 | 17/6/2026 | The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html by implementing CIP… | |
| Modificada | Crítica (9.8) | 0.92% | — | Netatalk | 16/6/2024 | 17/6/2026 | Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions. | |
| Modificada | Alta (7.5) | 0.88% | — | Netatalk | 16/6/2024 | 17/6/2026 | Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vulnerability. This… | |
| Modificada | Crítica (9.8) | 0.93% | — | Netatalk | 16/6/2024 | 17/6/2026 | Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions. | |
| Analizada | Alta (8.5) | 0.33% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system. | |
| Analizada | Alta (8.2) | 0.50% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication… | |
| Modificada | Alta (8.2) | 0.50% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification. | |
| Aplazada | Crítica (9.6) | 0.52% | — | Kakaocorp KakaotalkAI | 3/6/2024 | 17/6/2026 | A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to… | |
| Analizada | Alta (8.8) | 0.35% | — | Codester Astrotalks | 31/5/2024 | 17/6/2026 | Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the application as an administrator without any provided credentials, allowing the attacker to perform administrative actions. | |
| Analizada | Media (5.3) | 0.31% | — | Codester Astrotalks | 31/5/2024 | 17/6/2026 | Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials. | |
| Analizada | Alta (8.8) | 0.37% | — | Codester Astrotalks | 31/5/2024 | 17/6/2026 | SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database. | |
| Analizada | Alta (8.8) | 0.65% | — | Rockwellautomation Factorytalk View | 16/5/2024 | 17/6/2026 | A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure,… | |
| Aplazada | Alta (7) | 0.27% | 💥 PoC | Rockwellautomation Factorytalk Remote AccessAI | 16/5/2024 | 17/6/2026 | An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a… | |
| Aplazada | Alta (8.2) | 0.33% | — | Dectalk-ttsAI | 4/4/2024 | 17/6/2026 | dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `dectalk-tts@1.0.0`, network requests to the third-party API are sent over HTTP, which is unencrypted. Unencrypted traffic can be easily intercepted and modified by attackers. Anyone who uses the package could be the victim of a… | |
| Analizada | Media (5.3) | 0.66% | — | Rockwellautomation Factorytalk View | 25/3/2024 | 17/6/2026 | A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product. |