Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.24% | — | Cleantalk Anti-spam | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20. | |
| Analizada | Alta (8.8) | 0.99% | — | Rockwellautomation Factorytalk Services Platform | 16/2/2024 | 17/6/2026 | A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive… | |
| Modificada | Crítica (9.1) | 0.86% | — | Rockwellautomation Factorytalk Services Platform | 31/1/2024 | 17/6/2026 | A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory. If exploited, a malicious user could… | |
| Modificada | Alta (8.8) | 0.23% | — | Cleantalk Spam Protection, Antispam, Firewall | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20. | |
| Modificada | Alta (7.5) | 0.65% | — | Cleantalk Security & Malware Scan | 27/11/2023 | 17/6/2026 | The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection. | |
| Modificada | Alta (8.1) | 2.7% | — | Rockwellautomation Factorytalk Services Platform | 27/10/2023 | 17/6/2026 | Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user… | |
| Modificada | Alta (7.5) | 0.90% | — | Rockwellautomation Factorytalk View | 27/10/2023 | 17/6/2026 | Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition. | |
| Modificada | Alta (8.8) | 0.96% | — | Cleantalk Security & Malware Scan | 20/10/2023 | 17/6/2026 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and nonce disclosure in the source page of the administrative dashboard. This makes it possible for… | |
| Modificada | Media (4.3) | 0.48% | — | Nextcloud Talk | 16/10/2023 | 17/6/2026 | Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was an endpoint validating the conversation password without registering bruteforce attempts. It is recommended that the Nextcloud Talk app is… | |
| Modificada | Crítica (9.1) | 9.6% | — | Rockwellautomation Factorytalk Linx | 13/10/2023 | 17/6/2026 | FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes… | |
| Modificada | Crítica (9.8) | 2.1% | — | NetatalkDebian Linux | 20/9/2023 | 17/6/2026 | A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the underlying… | |
| Modificada | Crítica (9.8) | 17% | — | Rockwellautomation Factorytalk View | 12/9/2023 | 17/6/2026 | Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the functionality, through a CIP class, to execute exported functions from libraries. There… | |
| Modificada | Alta (7.8) | 0.37% | — | Nextcloud Talk | 10/8/2023 | 17/6/2026 | Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud Talk Android version 17.0.0 has a patch… | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Factorytalk Transaction Manager | 13/6/2023 | 17/6/2026 | A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage condition, causing intermittent application… | |
| Modificada | Media (4.7) | 0.38% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a legitimate local client device. This may allow a threat actor to craft a malicious… | |
| Modificada | Media (5) | 0.20% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected. Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives. This vulnerability may allow a local, authenticated non-admin user to craft a… | |
| Modificada | Alta (8.2) | 0.20% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies. Hard-coded cryptographic key may lead to privilege escalation. This vulnerability may allow a local, authenticated non-admin user to generate an invalid administrator cookie giving them… | |
| Modificada | Alta (8.8) | 0.38% | — | Rockwellautomation Factorytalk Vantagepoint | 11/5/2023 | 17/6/2026 | A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could… | |
| Modificada | Media (4.3) | 0.66% | — | Nextcloud Talk | 17/4/2023 | 17/6/2026 | Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that… | |
| Modificada | Baja (3.5) | 0.45% | — | Nextcloud Talk | 31/3/2023 | 17/6/2026 | Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members.… | |
| Modificada | Crítica (9.8) | 19% | — | Netatalk | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dsi_writeinit function. The issue results from the lack of proper validation of the length of user-supplied data… | |
| Modificada | Crítica (9.8) | 4.4% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not properly validate the length of… | |
| Modificada | Crítica (9.8) | 2.8% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper validation of user-supplied data, which… | |
| Modificada | Crítica (9.8) | 3.8% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue results from the lack of proper validation of user-supplied data, which… | |
| Modificada | Crítica (9.8) | 4.4% | — | NetatalkDebian Linux | 28/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results from the lack of proper validation of the length of user-supplied data… |