Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

209 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.4%—Netscout Ngeniusone2/6/202217/6/2026
NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
ModificadaAlta (8.8)0.98%—Netscout Ngeniusone2/6/202217/6/2026
NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
ModificadaCrítica (9.8)1.1%—Netscout Ngeniusone2/6/202217/6/2026
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
ModificadaAlta (8.2)1.2%💥 PoCClinical-genomics Scout5/5/202217/6/2026
Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...
ModificadaAlta (7.5)1.4%—Clinical-genomics Scout3/5/202217/6/2026
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.
ModificadaMedia (5.5)0.22%—Forescout Secureconnector29/12/202117/6/2026
ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash.
ModificadaMedia (5.4)0.43%—Netscout Ngeniusone30/9/202117/6/2026
NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.
ModificadaMedia (5.4)0.47%—Netscout Ngeniusone30/9/202117/6/2026
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Reflected Cross-Site Scripting (XSS) in the support endpoint.
ModificadaMedia (5.7)0.72%—Netscout Ngeniusone30/9/202117/6/2026
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.
ModificadaMedia (4.3)0.66%—Netscout Ngeniusone30/9/202117/6/2026
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.
ModificadaMedia (6.5)0.96%—Netscout Ngeniusone30/9/202117/6/2026
NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.
ModificadaMedia (4.8)0.46%—Netscout Ngeniusone30/9/202117/6/2026
NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQueryService.
ModificadaMedia (5.4)0.47%—Netscout Ngeniusone30/9/202117/6/2026
NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile.
ModificadaMedia (5.4)0.47%—Netscout Ngeniusone30/9/202117/6/2026
NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module.
ModificadaMedia (5.4)0.66%—Purethemes WorkscoutPurethemes Workscout Core6/5/202117/6/2026
The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues
ModificadaAlta (7.8)0.41%—Forescout Counteract14/4/202117/6/2026
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureConnector runs with administrative privileges and writes logs entries to a file in %PROGRAMDATA%\ForeScout SecureConnector\ that has full permissions for the Everyone…
ModificadaCrítica (9.8)7.9%💥 ExploitWoocommerce Help Scout5/4/202117/6/2026
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.
ModificadaCrítica (9.8)5.3%—Flexense Dupscout9/12/202017/6/2026
A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.
ModificadaAlta (8.1)1.2%—Netscout Airmagnet Enterprise3/12/202017/6/2026
NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward…
ModificadaMedia (5.4)1.2%—Scoutnet Kalender12/12/201917/6/2026
The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.
ModificadaAlta (7.5)1.7%—Telenav Scout GPS Link12/8/201917/6/2026
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easier for attackers to obtain multimedia-screen access via port 7050 on the cellular network, as demonstrated by a…
ModificadaAlta (8.8)2.5%—Hiscout GRC Suite13/9/201817/6/2026
HiScout GRC Suite before 3.1.5 allows Unrestricted Upload of Files with Dangerous Types.
ModificadaAlta (7.8)1.3%—Forescout Secureconnector13/7/201817/6/2026
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows service under the local SYSTEM account. The SecureConnector agent runs various…
ModificadaAlta (7.8)1.3%—Forescout Secureconnector13/7/201817/6/2026
On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows service under the local SYSTEM account. The SecureConnector agent runs various…
ModificadaMedia (6.1)0.69%—Flexense Dupscout2/5/201817/6/2026
XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7.
Orbitaley — Vulnerabilidades