Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.88% | — | Omron Machine Automation Controller NJ SeriesAIOmron Machine Automation Controller NX SeriesAI | 12/3/2024 | 17/6/2026 | Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege.… | |
| Analizada | Crítica (9.8) | 1.4% | — | Dell Recoverpoint FOR Virtual Machines | 16/2/2024 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete… | |
| Analizada | Crítica (9.8) | 0.46% | — | Dell Recoverpoint FOR Virtual Machines | 16/2/2024 | 17/6/2026 | Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint login form. This allows attackers to… | |
| Modificada | Alta (7.3) | 1.1% | — | Microsoft Azure Connected Machine Agent | 13/2/2024 | 10/8/2026 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | |
| Modificada | Media (6.5) | 0.58% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access. An attacker with access to the internal procedures could view… | |
| Modificada | Crítica (9.1) | 0.80% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication. | |
| Modificada | Alta (8.1) | 0.39% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack. | |
| Modificada | Alta (7.5) | 0.59% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users. | |
| Modificada | Alta (8.8) | 0.40% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device. | |
| Modificada | Crítica (9.8) | 0.65% | — | Machinesense Feverwarn Firmware | 1/2/2024 | 17/6/2026 | Multiple MachineSense devices have credentials unable to be changed by the user or administrator. | |
| Modificada | Crítica (9.1) | 1.1% | — | Rmountjoy92 Dashmachine | 17/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may… | |
| Modificada | Crítica (9.8) | 1.0% | — | Rmountjoy92 Dashmachine | 17/12/2023 | 17/6/2026 | A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of the file /settings/save_config of the component Config Handler. The manipulation of the argument value_template leads to code injection. The exploit has been disclosed to… | |
| Modificada | Media (4.7) | 0.71% | — | Microsoft Azure Machine Learning Software Development KIT | 12/12/2023 | 17/6/2026 | Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability | |
| Modificada | Alta (7.3) | 0.88% | — | Microsoft Azure Connected Machine Agent | 12/12/2023 | 17/6/2026 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | |
| Modificada | Media (6.1) | 0.61% | — | Mldb Machine Learning Database | 9/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html. | |
| Modificada | Media (6.5) | 0.90% | — | Docker Machine | 7/11/2023 | 17/6/2026 | Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.1) | 1.2% | — | Nomachine | 4/8/2023 | 17/6/2026 | An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks. | |
| Modificada | Media (6.5) | 0.64% | — | Vmware Isolation SegmentVmware Tanzu Application Service FOR Virtual Machines | 26/7/2023 | 17/6/2026 | The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials… | |
| Modificada | Crítica (9.8) | 1.3% | — | Stw-mobile-machines Tcg-4 FirmwareStw-mobile-machines Tcg-4lite Firmware | 29/6/2023 | 17/6/2026 | STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without the need for authentication, giving an… | |
| Modificada | Media (6.5) | 0.40% | — | IBM Watson Machine Learning ON Cloud PAK FOR Data | 27/4/2023 | 17/6/2026 | IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350. | |
| Modificada | Media (6.5) | 1.5% | — | Microsoft Azure Machine Learning | 11/4/2023 | 17/6/2026 | Azure Machine Learning Information Disclosure Vulnerability | |
| Modificada | Crítica (9.8) | 0.71% | — | Tosec Kirin Fortress Machine | 16/3/2023 | 17/6/2026 | SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter. | |
| Modificada | Crítica (9.8) | 0.89% | — | Propius Machineselector | 14/3/2023 | 17/6/2026 | A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system. | |
| Modificada | Crítica (9.8) | 0.85% | — | UI Unifi Dream Machine PRO Firmware | 23/2/2023 | 17/6/2026 | Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets. |