Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.84%—Oracle Java Virtual Machine21/7/202117/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this…
ModificadaAlta (7.4)0.49%—Siemens Sinumerik Analyse Mycondition FirmwareSiemens Sinumerik Analyze Myperformance FirmwareSiemens Sinumerik Integrate Client FirmwareSiemens Sinumerik Integrate FOR Production Firmware+613/7/202117/6/2026
A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 <…
ModificadaMedia (6.5)0.87%—Redhat Machine-config-operator7/6/202117/6/2026
A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memory. An attacker could use this flaw to deny access to schedule new pods in the OpenShift cluster. This was fixed in openshift/machine-config-operator 4.4.3,…
ModificadaAlta (7.8)0.25%—Schneider-electric Vijeo DesignerSchneider-electric Ecostruxure Machine Expert26/5/202117/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
ModificadaAlta (7.8)0.85%💥 PoCMIT Universal Turing Machine10/5/202117/6/2026
Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code via crafted data. For example, a tape head may have an unexpected location after the processing of input composed of As and Bs (instead of 0s and 1s). NOTE: the…
ModificadaMedia (5.3)1.1%—Thecodingmachine Gotenberg26/2/202117/6/2026
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as <iframe src='file:///etc/passwd'>.
ModificadaMedia (5.9)0.52%—Tenable Nessus Amazon Machine Image6/2/202117/6/2026
Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
ModificadaCrítica (9.8)2.9%—Thecodingmachine Gotenberg7/1/202117/6/2026
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
ModificadaCrítica (9.8)3.2%—Thecodingmachine Gotenberg7/1/202117/6/2026
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
ModificadaCrítica (9.8)5.8%—Thecodingmachine Gotenberg7/1/202117/6/2026
A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.
ModificadaAlta (7.5)5.0%—Thecodingmachine Gotenberg7/1/202117/6/2026
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.
ModificadaMedia (6.8)1.1%—Schneider-electric Modicon M258 FirmwareSchneider-electric SomachineSchneider-electric Somachine Motion11/12/202017/6/2026
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not…
ModificadaBaja (3.1)0.75%—Oracle Java Virtual Machine21/10/202017/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via multiple protocols to compromise Java VM.…
ModificadaMedia (5.7)0.71%—Vmware Tanzu Application Service FOR Virtual MachinesVmware Operations Manager31/7/202017/6/2026
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the unredacted logs are available to…
ModificadaAlta (8.8)1.9%—Vmware GemfireVmware Tanzu Gemfire FOR Virtual Machines31/7/202017/6/2026
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a malicious user to create an MLet mbean leading…
ModificadaCrítica (9.1)1.8%—Vmware GemfireVmware Tanzu Gemfire FOR Virtual Machines31/7/202017/6/2026
VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may request against the service with a…
ModificadaCrítica (9.8)1.6%—Schneider-electric Ecostruxure Machine ExpertSchneider-electric Somachine BasicSchneider-electric Modicon M100 FirmwareSchneider-electric Modicon M200 Firmware+122/4/202017/6/2026
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the…
ModificadaAlta (7.5)0.88%—Schneider-electric Ecostruxure Machine ExpertSchneider-electric SomachineSchneider-electric Somachine MotionSchneider-electric Modicon M218 Firmware+322/4/202017/6/2026
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.
ModificadaCrítica (9.8)0.69%—Schneider-electric Ecostruxure Machine ExpertSchneider-electric SomachineSchneider-electric Somachine MotionSchneider-electric Modicon M218 Firmware+322/4/202017/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.
ModificadaCrítica (9.8)1.5%—Simplemachines Simple Machine Forum20/3/202017/6/2026
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
ModificadaMedia (6.1)0.99%—Simplemachines Simple Machines Forum12/2/202016/6/2026
Simple Machines Forum (SMF) through 2.0.5 has XSS
ModificadaMedia (4.9)3.8%💥 ExploitSimplemachines Simple Machines Forum7/2/202016/6/2026
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
ModificadaMedia (6.5)1.3%—Simplemachines Simple Machines Forum22/1/202017/6/2026
An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.
ModificadaAlta (7.2)1.7%💥 ExploitSimplemachines Simple Machines Forum15/1/202016/6/2026
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain…
ModificadaCrítica (9.8)1.7%💥 ExploitSimplemachines Simple Machine Forum15/1/202016/6/2026
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
Orbitaley — Vulnerabilidades