Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)4.9%—Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal UnitEmerson DL 8000 Remote Terminal Unit3/10/201316/6/2026
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service.
ModificadaAlta (10)5.0%—Enea OSEEmerson ROC 800l Remote Terminal UnitEmerson ROC 800 Remote Terminal UnitEmerson DL 8000 Remote Terminal Unit3/10/201316/6/2026
The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors.
ModificadaAlta (7.8)1.5%—Synel Sy-780/a Time & Attendance Terminal9/7/201216/6/2026
The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network traffic to port (1) 1641, (2) 3734, or (3) 3735.
ModificadaMedia (6.8)0.59%—Typo3 Terminal14/2/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaBaja (3.5)0.85%—Typo3 Terminal14/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)0.98%—Apple TerminalApple MAC OS XApple MAC OS X Server23/3/201116/6/2026
The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulnerabilities.
ModificadaMedia (6.8)4.5%💥 ExploitErick Woods Terminal Server Client7/2/201116/6/2026
Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allow user-assisted remote attackers to execute arbitrary code via a .RDP file with a long (1) username, (2) password, or (3) domain argument. NOTE: the…
ModificadaMedia (6.8)5.2%💥 ExploitErick Woods Terminal Server Client7/2/201116/6/2026
Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a .RDP file with a long hostname argument.
ModificadaMedia (6.9)0.35%—Jonas Smedegaard Sdm-terminal8/12/200816/6/2026
sdm-login in sdm-terminal 0.4.0b allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sdm.autologin.once temporary file.
ModificadaMedia (6.9)0.34%—Mohammed Sameer Multi-gnome-terminal18/11/200816/6/2026
mgt-helper in multi-gnome-terminal 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.debug or (2) /tmp/*.env temporary file.
ModificadaMedia (4.8)1.2%—Ltsp Linux Terminal Server Project29/4/200816/6/2026
ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which allows remote attackers to connect to this server via TCP port 6006 (aka display :6).
ModificadaAlta (7.8)2.2%—Os-cillation Xfce Terminal15/7/200716/6/2026
The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the "Open Link" functionality.
ModificadaAlta (7.5)9.4%—Microsoft Terminal Server11/5/200716/6/2026
The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0…
ModificadaAlta (10)9.4%—Microsoft Terminal Server31/8/200616/6/2026
Microsoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client Connection Manager wizard" options, allows local users to execute arbitrary code by forcing an Explorer error. NOTE: a third-party researcher has stated that the options…
ModificadaAlta (10)2.5%—Ak-systems Windows Terminal23/8/200616/6/2026
VNC server on the AK-Systems Windows Terminal 1.2.5 ExVLP is not password protected, which allows remote attackers to login and view RDP or Citrix sessions.
ModificadaAlta (7.8)53%💥 ExploitFilezilla Server Terminal16/11/200516/6/2026
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.
ModificadaAlta (7.5)25%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+314/6/200516/6/2026
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
ModificadaMedia (5.1)13%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows 2003 ServerMicrosoft Windows 98+314/6/200516/6/2026
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.
ModificadaAlta (7.4)16%💥 PoCMicrosoft Remote Desktop ConnectionMicrosoft Windows Terminal Services Using RDP1/6/200516/6/2026
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
ModificadaMedia (5.1)3.1%—Apple TerminalApple MAC OS XApple MAC OS X Server4/5/200516/6/2026
Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
ModificadaAlta (7.5)5.2%—Apple TerminalApple MAC OS X4/5/200516/6/2026
The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.
ModificadaAlta (7.2)4.6%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2000 Terminal Services18/8/200316/6/2026
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
ModificadaMedia (4.6)2.2%—Microsoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NTMicrosoft Windows XP12/5/200316/6/2026
Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
ModificadaAlta (7.5)37%💥 ExploitMicrosoft Virtual MachineMicrosoft Windows 2000Microsoft Windows 2000 Terminal Services5/5/200316/6/2026
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."
ModificadaMedia (5)38%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NTMicrosoft Windows XP2/4/200316/6/2026
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.
Orbitaley — Vulnerabilidades