Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.88%—Omron Machine Automation Controller NJ SeriesAIOmron Machine Automation Controller NX SeriesAI12/3/202417/6/2026
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege.…
AnalizadaCrítica (9.8)1.4%—Dell Recoverpoint FOR Virtual Machines16/2/202417/6/2026
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete…
AnalizadaCrítica (9.8)0.46%—Dell Recoverpoint FOR Virtual Machines16/2/202417/6/2026
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to launch a brute force attack or a dictionary attack against the RecoverPoint login form. This allows attackers to…
ModificadaAlta (7.3)1.1%—Microsoft Azure Connected Machine Agent13/2/202410/8/2026
Azure Connected Machine Agent Elevation of Privilege Vulnerability
ModificadaMedia (6.5)0.58%—Machinesense Feverwarn Firmware1/2/202417/6/2026
The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access. An attacker with access to the internal procedures could view…
ModificadaCrítica (9.1)0.80%—Machinesense Feverwarn Firmware1/2/202417/6/2026
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication.
ModificadaAlta (8.1)0.39%—Machinesense Feverwarn Firmware1/2/202417/6/2026
MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.
ModificadaAlta (7.5)0.59%—Machinesense Feverwarn Firmware1/2/202417/6/2026
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.
ModificadaAlta (8.8)0.40%—Machinesense Feverwarn Firmware1/2/202417/6/2026
MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device.
ModificadaCrítica (9.8)0.65%—Machinesense Feverwarn Firmware1/2/202417/6/2026
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
ModificadaCrítica (9.1)1.1%—Rmountjoy92 Dashmachine17/12/202317/6/2026
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may…
ModificadaCrítica (9.8)1.0%—Rmountjoy92 Dashmachine17/12/202317/6/2026
A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of the file /settings/save_config of the component Config Handler. The manipulation of the argument value_template leads to code injection. The exploit has been disclosed to…
ModificadaMedia (4.7)0.71%—Microsoft Azure Machine Learning Software Development KIT12/12/202317/6/2026
Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
ModificadaAlta (7.3)0.88%—Microsoft Azure Connected Machine Agent12/12/202317/6/2026
Azure Connected Machine Agent Elevation of Privilege Vulnerability
ModificadaMedia (6.1)0.61%—Mldb Machine Learning Database9/11/202317/6/2026
Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html.
ModificadaMedia (6.5)0.90%—Docker Machine7/11/202317/6/2026
Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This…
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaCrítica (9.1)1.2%—Nomachine4/8/202317/6/2026
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.
ModificadaMedia (6.5)0.64%—Vmware Isolation SegmentVmware Tanzu Application Service FOR Virtual Machines26/7/202317/6/2026
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials…
ModificadaCrítica (9.8)1.3%—Stw-mobile-machines Tcg-4 FirmwareStw-mobile-machines Tcg-4lite Firmware29/6/202317/6/2026
STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without the need for authentication, giving an…
ModificadaMedia (6.5)0.40%—IBM Watson Machine Learning ON Cloud PAK FOR Data27/4/202317/6/2026
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
ModificadaMedia (6.5)1.5%—Microsoft Azure Machine Learning11/4/202317/6/2026
Azure Machine Learning Information Disclosure Vulnerability
ModificadaCrítica (9.8)0.71%—Tosec Kirin Fortress Machine16/3/202317/6/2026
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.
ModificadaCrítica (9.8)0.89%—Propius Machineselector14/3/202317/6/2026
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.
ModificadaCrítica (9.8)0.85%—UI Unifi Dream Machine PRO Firmware23/2/202317/6/2026
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.