Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

352 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)8.6%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error handling when parsing AppleDouble…
ModificadaCrítica (9.8)4.4%—NetatalkDebian Linux28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper validation of the length of user-supplied data…
ModificadaMedia (6.1)0.56%—Mirotalk P2P22/3/202317/6/2026
A cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the settings module.
ModificadaMedia (4.3)0.80%—Nextcloud Talk27/2/202317/6/2026
Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. It is recommended that the Nextcloud Talk is upgraded to 15.0.3. There are no…
ModificadaBaja (2.1)0.56%—Nextcloud Talk9/1/202317/6/2026
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds…
ModificadaMedia (6.5)0.82%—Nextcloud Talk1/12/202217/6/2026
Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call in a public conversation after being…
ModificadaMedia (5.5)0.28%—Nextcloud Talk25/11/202217/6/2026
Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broadcastPermission allowing malicious apps to monitor communication. It is recommended that the Nextcloud Talk Android is upgraded to 14.1.0. There are no known workarounds…
ModificadaAlta (7.8)0.61%—NetatalkDebian LinuxFedoraproject Fedora12/11/202217/6/2026
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
ModificadaAlta (7.5)1.2%—Rockwellautomation Factorytalk Alarms AND Events27/10/202217/6/2026
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.
ModificadaAlta (7.2)1.1%—Cleantalk Spam Protection, Antispam, Firewall25/10/202217/6/2026
The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin
ModificadaAlta (8.8)3.5%—Rockwellautomation Factorytalk Vantagepoint17/10/202217/6/2026
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could…
ModificadaAlta (8.8)1.4%—Rockwellautomation Factorytalk Vantagepoint17/10/202217/6/2026
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully…
ModificadaMedia (5.3)0.68%—Nextcloud Talk17/9/202217/6/2026
Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected. It is recommended that the Nextcloud Talk app is upgraded to 13.0.8 or 14.0.4. Users unable to…
ModificadaMedia (5.3)1.4%—Nextcloud Talk12/8/202217/6/2026
Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It is recommended that the Nextcloud Talk application is upgraded to 12.2.7, 13.0.7…
ModificadaMedia (4.3)0.94%—Nextcloud Talk17/5/202217/6/2026
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known…
ModificadaMedia (6.1)0.94%—Nextcloud Talk27/4/202217/6/2026
Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs. This issue is fixed in versions 11.3.4,…
ModificadaMedia (6.1)2.9%—Cleantalk Antispam19/4/202217/6/2026
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php`
ModificadaMedia (6.1)2.4%—Cleantalk Antispam19/4/202217/6/2026
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php`
ModificadaAlta (8.8)2.4%—Rockwellautomation Factorytalk Services Platform1/4/202217/6/2026
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have…
ModificadaCrítica (9.8)2.7%—Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+925/3/202217/6/2026
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
ModificadaCrítica (9.8)4.1%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
ModificadaAlta (7.5)1.6%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)5.7%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
ModificadaCrítica (9.8)3.8%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.5%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
Orbitaley — Vulnerabilidades