Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

5122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.21%—Datakit Crosscadware20/4/202317/6/2026
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
ModificadaMedia (5.5)0.21%—Datakit Crosscadware20/4/202317/6/2026
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
ModificadaMedia (5.5)0.21%—Datakit Crosscadware20/4/202317/6/2026
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
ModificadaMedia (5.5)0.21%—Datakit Crosscadware20/4/202317/6/2026
Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
ModificadaAlta (8.1)0.82%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (7.8)0.59%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected products: StruxureWare Data Center Expert (V7.9.2…
ModificadaMedia (6.1)0.39%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.1)0.50%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.1)0.40%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaCrítica (9.8)1.2%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaCrítica (9.8)1.2%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.5)0.55%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly secured when a hacker is using a low privileged user. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.8)0.94%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using a low privileged user account. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.5)0.62%—Oracle Clinical Remote Data Capture18/4/202317/6/2026
Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture.…
ModificadaMedia (6.8)0.54%—Oracle Database18/4/202317/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having User Account privilege with network access via TLS to compromise Java VM. Successful attacks of this vulnerability can result…
ModificadaMedia (6.8)0.67%—Oracle Database Recovery Manager18/4/202317/6/2026
Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local SYSDBA privilege with network access via Oracle Net to compromise Oracle Database Recovery…
ModificadaCrítica (9.8)2.4%—Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware14/4/202317/6/2026
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
ModificadaAlta (8.8)17%—Iodata Wfs-sr03w FirmwareIodata Wfs-sr03k Firmware14/4/202317/6/2026
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.
ModificadaMedia (5.3)1.1%—Datagear14/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functionality of the component JDBC Server Handler. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and…
ModificadaMedia (5.5)0.21%—Talend Data Catalog13/4/202317/6/2026
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.
ModificadaMedia (5.5)0.22%—Talend Data Catalog13/4/202317/6/2026
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/license endpoint of the remote harvesting server.
ModificadaAlta (8.8)2.7%💥 PoCWpdataaccess WP Data Access12/4/202317/6/2026
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their…
ModificadaAlta (7.8)0.38%—Treasuredata Fluent BIT11/4/202317/6/2026
An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in flb_msgpack_gelf_value_ext. An attacker can craft a malicious file and tick the victim to open the file with the software, triggering a heap overflow and execute arbitrary code on…
ModificadaAlta (7.8)0.35%—Treasuredata Fluent BIT11/4/202317/6/2026
An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug that interprets whatever is on the stack as msgpack maps and arrays, leading to use-after-free. This can be used by an attacker to craft a specially craft file and trick the…
ModificadaAlta (8.8)0.77%—Dell Powerprotect Data Manager11/4/202317/6/2026
Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and perform unauthorized actions.