Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | Pexip InfinityPexip Reverse Proxy AND Turn Server | 25/9/2020 | 17/6/2026 | Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN. | |
| Modificada | Media (4.4) | 0.28% | — | Hcltechsw HCL Verse | 15/7/2020 | 17/6/2026 | "HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtime; however, dynamically… | |
| Modificada | Alta (7.8) | 0.41% | — | Broadcom CA Automic Dollar Universe | 8/1/2020 | 17/6/2026 | CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability was reported to CA several years after CA Automic Dollar Universe 5.3.3 reached End of Life (EOL) status on April 1, 2015. | |
| Modificada | Media (6.1) | 1.0% | — | Django JS Reverse Project Django JS Reserve | 23/8/2019 | 17/6/2026 | django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline. | |
| Modificada | Media (5.5) | 0.66% | — | Huawei Pcmanager(china)Huawei Pcmanager(oversea) | 8/8/2019 | 17/6/2026 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information leak vulnerability. Successful exploitation may cause the attacker to read information. | |
| Modificada | Alta (7.8) | 0.86% | — | Huawei Pcmanager(china)Huawei Pcmanager(oversea) | 8/8/2019 | 17/6/2026 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. Successful exploitation may cause the attacker to execute code and read/write information. | |
| Modificada | Alta (7.8) | 0.86% | — | Huawei Pcmanager(china)Huawei Pcmanager(oversea) | 8/8/2019 | 17/6/2026 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. Successful exploitation may cause the attacker to execute code and read/write information. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Thephpfactory Reverse Auction Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter. | |
| Modificada | Crítica (9.8) | 0.84% | — | Schneider-electric 66074 MGE Network Management Card Transverse | 18/4/2018 | 17/6/2026 | A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default… | |
| Modificada | Crítica (9.1) | 1.2% | — | Schneider-electric 66074 MGE Network Management Card Transverse | 18/4/2018 | 17/6/2026 | An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical… | |
| Modificada | Media (5.3) | 1.0% | — | Schneider-electric 66074 MGE Network Management Card Transverse | 18/4/2018 | 17/6/2026 | An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to obtain sensitive device information if network access was obtained. | |
| Modificada | Crítica (9.8) | 2.8% | — | Schneider-electric 66074 MGE Network Management Card Transverse | 18/4/2018 | 17/6/2026 | An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system. | |
| Modificada | Baja (3.3) | 0.34% | — | Jenkins Reverse Proxy Auth | 5/4/2018 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users. | |
| Modificada | Media (5.3) | 1.1% | — | Conversejs Converse.js | 19/2/2018 | 17/6/2026 | Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended. For example, users might have an expectation that chatroom bookmarks are private, but the various interacting… | |
| Modificada | Crítica (9.8) | 3.8% | 💥 Exploit | Jextn Reverse Auction | 2/2/2018 | 17/6/2026 | SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (5.9) | 8.0% | — | ATT U-verse Firmware | 3/9/2017 | 17/6/2026 | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated proxy service on WAN TCP port 49152, which allows remote attackers to establish arbitrary TCP connections to intranet hosts by sending \x2a\xce\x01 followed by other… | |
| Modificada | Alta (8.1) | 3.3% | — | ATT U-verse Firmware | 3/9/2017 | 17/6/2026 | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https service with the tech account and an empty password, which allows remote attackers to obtain root privileges by establishing a session on port 49955 and then installing new… | |
| Modificada | Alta (8.1) | 4.4% | — | ATT U-verse Firmware | 3/9/2017 | 17/6/2026 | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent-enable WAN SSH logins to the remotessh account with the 5SaP9I26 password, which allows remote attackers to access a "Terminal shell v1.0" service, and subsequently obtain… | |
| Modificada | Alta (8.1) | 2.8% | — | ATT U-verse Firmware | 3/9/2017 | 17/6/2026 | The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an sbdc.ha WAN TCP service on port 61001 with the bdctest account and the bdctest password, which allows remote attackers to obtain sensitive information (such as the Wi-Fi… | |
| Modificada | Alta (7.5) | 1.1% | — | Inversepath Tenshi | 30/7/2017 | 17/6/2026 | Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification before a root script executes a "kill `cat /pathname/tenshi.pid`" command. | |
| Modificada | Media (4.3) | 1.2% | — | Inverse-inc Sogo | 17/2/2017 | 17/6/2026 | SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users. | |
| Modificada | Media (5.9) | 0.94% | — | Conversejs Converse.js | 9/2/2017 | 17/6/2026 | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Converse.js (0.8.0 - 1.0.6, 2.0.0 - 2.0.4). | |
| Modificada | Media (5.4) | 0.29% | — | Nasa Universe Wallpapers Xeus Project Nasa Universe Wallpapers Xeus | 19/10/2014 | 17/6/2026 | The NASA Universe Wallpapers Xeus (aka com.xeusNASA) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Ben10 Omniverse Walkthrough Project Ben10 Omniverse Walkthrough | 19/10/2014 | 17/6/2026 | The ben10 omniverse walkthrough (aka com.wben10omniverse2walkthrough) application 0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |