Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | Netscout Ngeniusone | 2/6/2022 | 17/6/2026 | NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution. | |
| Modificada | Alta (8.8) | 0.98% | — | Netscout Ngeniusone | 2/6/2022 | 17/6/2026 | NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. | |
| Modificada | Crítica (9.8) | 1.1% | — | Netscout Ngeniusone | 2/6/2022 | 17/6/2026 | NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. | |
| Modificada | Alta (8.2) | 1.2% | 💥 PoC | Clinical-genomics Scout | 5/5/2022 | 17/6/2026 | Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss... | |
| Modificada | Alta (7.5) | 1.4% | — | Clinical-genomics Scout | 3/5/2022 | 17/6/2026 | Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52. | |
| Modificada | Media (5.5) | 0.22% | — | Forescout Secureconnector | 29/12/2021 | 17/6/2026 | ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash. | |
| Modificada | Media (5.4) | 0.43% | — | Netscout Ngeniusone | 30/9/2021 | 17/6/2026 | NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector. | |
| Modificada | Media (5.4) | 0.47% | — | Netscout Ngeniusone | 30/9/2021 | 17/6/2026 | NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Reflected Cross-Site Scripting (XSS) in the support endpoint. | |
| Modificada | Media (5.7) | 0.72% | — | Netscout Ngeniusone | 30/9/2021 | 17/6/2026 | NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint. | |
| Modificada | Media (4.3) | 0.66% | — | Netscout Ngeniusone | 30/9/2021 | 17/6/2026 | NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService. | |
| Modificada | Media (6.5) | 0.96% | — | Netscout Ngeniusone | 30/9/2021 | 17/6/2026 | NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks. | |
| Modificada | Media (4.8) | 0.46% | — | Netscout Ngeniusone | 30/9/2021 | 17/6/2026 | NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQueryService. | |
| Modificada | Media (5.4) | 0.47% | — | Netscout Ngeniusone | 30/9/2021 | 17/6/2026 | NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile. | |
| Modificada | Media (5.4) | 0.47% | — | Netscout Ngeniusone | 30/9/2021 | 17/6/2026 | NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module. | |
| Modificada | Media (5.4) | 0.66% | — | Purethemes WorkscoutPurethemes Workscout Core | 6/5/2021 | 17/6/2026 | The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues | |
| Modificada | Alta (7.8) | 0.41% | — | Forescout Counteract | 14/4/2021 | 17/6/2026 | An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMDATA%\ForeScout SecureConnector\ that has full permissions for the Everyone… | |
| Modificada | Crítica (9.8) | 7.9% | 💥 Exploit | Woocommerce Help Scout | 5/4/2021 | 17/6/2026 | The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp. | |
| Modificada | Crítica (9.8) | 5.3% | — | Flexense Dupscout | 9/12/2020 | 17/6/2026 | A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack. | |
| Modificada | Alta (8.1) | 1.2% | — | Netscout Airmagnet Enterprise | 3/12/2020 | 17/6/2026 | NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward… | |
| Modificada | Media (5.4) | 1.2% | — | Scoutnet Kalender | 12/12/2019 | 17/6/2026 | The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS. | |
| Modificada | Alta (7.5) | 1.7% | — | Telenav Scout GPS Link | 12/8/2019 | 17/6/2026 | The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easier for attackers to obtain multimedia-screen access via port 7050 on the cellular network, as demonstrated by a… | |
| Modificada | Alta (8.8) | 2.5% | — | Hiscout GRC Suite | 13/9/2018 | 17/6/2026 | HiScout GRC Suite before 3.1.5 allows Unrestricted Upload of Files with Dangerous Types. | |
| Modificada | Alta (7.8) | 1.3% | — | Forescout Secureconnector | 13/7/2018 | 17/6/2026 | On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows service under the local SYSTEM account. The SecureConnector agent runs various… | |
| Modificada | Alta (7.8) | 1.3% | — | Forescout Secureconnector | 13/7/2018 | 17/6/2026 | On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows service under the local SYSTEM account. The SecureConnector agent runs various… | |
| Modificada | Media (6.1) | 0.69% | — | Flexense Dupscout | 2/5/2018 | 17/6/2026 | XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7. |