Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

352 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.24%—Cleantalk Anti-spam29/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.
AnalizadaAlta (8.8)0.99%—Rockwellautomation Factorytalk Services Platform16/2/202417/6/2026
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive…
ModificadaCrítica (9.1)0.86%—Rockwellautomation Factorytalk Services Platform31/1/202417/6/2026
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory. If exploited, a malicious user could…
ModificadaAlta (8.8)0.23%—Cleantalk Spam Protection, Antispam, Firewall5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.
ModificadaAlta (7.5)0.65%—Cleantalk Security & Malware Scan27/11/202317/6/2026
The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.
ModificadaAlta (8.1)2.7%—Rockwellautomation Factorytalk Services Platform27/10/202317/6/2026
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user…
ModificadaAlta (7.5)0.90%—Rockwellautomation Factorytalk View27/10/202317/6/2026
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.
ModificadaAlta (8.8)0.96%—Cleantalk Security & Malware Scan20/10/202317/6/2026
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and nonce disclosure in the source page of the administrative dashboard. This makes it possible for…
ModificadaMedia (4.3)0.48%—Nextcloud Talk16/10/202317/6/2026
Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was an endpoint validating the conversation password without registering bruteforce attempts. It is recommended that the Nextcloud Talk app is…
ModificadaCrítica (9.1)9.6%—Rockwellautomation Factorytalk Linx13/10/202317/6/2026
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes…
ModificadaCrítica (9.8)2.1%—NetatalkDebian Linux20/9/202317/6/2026
A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the underlying…
ModificadaCrítica (9.8)17%—Rockwellautomation Factorytalk View12/9/202317/6/2026
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the functionality, through a CIP class, to execute exported functions from libraries. There…
ModificadaAlta (7.8)0.37%—Nextcloud Talk10/8/202317/6/2026
Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud Talk Android version 17.0.0 has a patch…
ModificadaAlta (7.5)1.2%—Rockwellautomation Factorytalk Transaction Manager13/6/202317/6/2026
A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage condition, causing intermittent application…
ModificadaMedia (4.7)0.38%—Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services13/6/202317/6/2026
The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a legitimate local client device. This may allow a threat actor to craft a malicious…
ModificadaMedia (5)0.20%—Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services13/6/202317/6/2026
Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected. Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives. This vulnerability may allow a local, authenticated non-admin user to craft a…
ModificadaAlta (8.2)0.20%—Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services13/6/202317/6/2026
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies. Hard-coded cryptographic key may lead to privilege escalation. This vulnerability may allow a local, authenticated non-admin user to generate an invalid administrator cookie giving them…
ModificadaAlta (8.8)0.38%—Rockwellautomation Factorytalk Vantagepoint11/5/202317/6/2026
A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could…
ModificadaMedia (4.3)0.66%—Nextcloud Talk17/4/202317/6/2026
Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that…
ModificadaBaja (3.5)0.45%—Nextcloud Talk31/3/202317/6/2026
Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members.…
ModificadaCrítica (9.8)19%—Netatalk29/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dsi_writeinit function. The issue results from the lack of proper validation of the length of user-supplied data…
ModificadaCrítica (9.8)4.4%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of…
ModificadaCrítica (9.8)2.8%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper validation of user-supplied data, which…
ModificadaCrítica (9.8)3.8%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue results from the lack of proper validation of user-supplied data, which…
ModificadaCrítica (9.8)4.4%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results from the lack of proper validation of the length of user-supplied data…