Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.62%—Siemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation PortalSiemens User Management Component13/5/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All…
AplazadaMedia (6.4)0.26%—Oliver Campion Display Remote Posts BlockAI7/5/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Oliver Campion Display Remote Posts Block display-remote-posts-block allows Server Side Request Forgery.This issue affects Display Remote Posts Block: from n/a through <= 1.1.0.
ModificadaAlta (7.3)0.19%—Beyondtrust Privileged Remote Access5/5/202517/6/2026
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.
AnalizadaMedia (5.4)0.23%—Checkpoint Mobile AccessCheckpoint Remote Access VPN27/4/202517/6/2026
For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.
AnalizadaMedia (5.4)0.22%—Checkpoint Mobile AccessCheckpoint Remote Access VPN27/4/202517/6/2026
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.
AplazadaAlta (7.5)0.91%—Mitsubishielectric Cc-link IE TSN Remote IO ModuleAIMitsubishielectric Cc-link IE TSN Analog-digital Converter ModuleAIMitsubishielectric Cc-link IE TSN Digital-analog Converter ModuleAIMitsubishielectric Cc-link IE TSN Fpga ModuleAI+825/4/202527/8/2026
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with…
AplazadaAlta (7.1)0.14%—Huangye Wudeng Hacklog Remote AttachmentAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment hacklog-remote-attachment allows Stored XSS.This issue affects Hacklog Remote Attachment: from n/a through <= 1.3.2.
AplazadaCrítica (9)0.92%—Jupyter Remote Desktop ProxyAITigervncAI15/4/202517/6/2026
Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the…
AplazadaCrítica (9.9)0.54%💥 PoCNirmal Kumar RAM WP Remote ThumbnailAI10/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This issue affects WP Remote Thumbnail: from n/a through <= 1.3.2.
AnalizadaAlta (8)1.5%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+138/4/202517/6/2026
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
AnalizadaMedia (5.5)0.28%—Jenkins Monitor-remote-job2/4/202517/6/2026
Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
ModificadaMedia (6.8)0.41%—Devolutions Remote Desktop Manager26/3/202517/6/2026
Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD variable even though not allowed by the "Allow password in variable policy". This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25,…
AnalizadaMedia (5.4)0.42%—Devolutions Remote Desktop Manager26/3/202517/6/2026
Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without generating a corresponding log event, via the use of the autotyping functionality. This issue affects Remote Desktop Manager versions from 2025.1.24 through…
AnalizadaBaja (3.6)0.17%—Devolutions Remote Desktop Manager26/3/202517/6/2026
Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions…
AnalizadaMedia (5.4)0.40%—Devolutions Remote Desktop Manager26/3/202517/6/2026
Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to bypass certain permission restrictions—specifically View Password, Edit Asset, and Edit Permissions by performing specific actions. This issue affects Remote…
AplazadaMedia (4.3)0.20%—Huangye Wudeng Hacklog Remote Image AutosaveAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Image Autosave hacklog-remote-image-autosave allows Cross Site Request Forgery.This issue affects Hacklog Remote Image Autosave: from n/a through <= 2.1.0.
AnalizadaMedia (6.5)1.8%—Devolutions Remote Desktop Manager13/3/202517/6/2026
Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows an authenticated user to inadvertently leak the My Personal Credentials in a shared vault via the clear history feature due to faulty business logic.
AnalizadaMedia (6.5)1.8%—Devolutions Remote Desktop Manager13/3/202517/6/2026
Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows a user exporting a hub data source to include his authenticated session in the export due to faulty business logic.
AnalizadaAlta (8.8)3.2%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1211/3/202517/6/2026
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AplazadaAlta (7.8)0.15%—Rsupport Remoteview AgentAI6/3/202517/6/2026
Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.
AplazadaAlta (7.8)0.15%—Remoteview AgentAI6/3/202517/6/2026
Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows) versions prior to v8.1.5.2. If this vulnerability is exploited, a non-administrative user on the remote PC may execute an arbitrary OS command with LocalSystem privilege.
AplazadaMedia (5.8)0.95%💥 PoCTsplus Remote AccessAI4/3/202517/6/2026
hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently connected to the application.
AplazadaAlta (8.8)1.7%💥 PoCNvda RemoteAITele Nvda RemoteAI28/2/202517/6/2026
A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain total control of the remote system by guessing a weak password. The problem occurs because these add-ons accept any password entered by the user and do…
AnalizadaAlta (8.1)0.39%—Devolutions Remote Desktop Manager10/2/202517/6/2026
Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack by presenting a certificate for a different host.
AnalizadaAlta (8.8)0.23%—Devolutions Remote Desktop ManagerDevolutions Remote Desktop Manager Powershell10/2/202517/6/2026
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and…
Orbitaley — Vulnerabilidades