Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.45% | — | Velneo Vclient | 23/9/2022 | 17/6/2026 | Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials. | |
| Analizada | Alta (7.8) | 0.49% | — | NeovimVIMFedoraproject FedoraDebian Linux | 22/9/2022 | 24/9/2026 | Use After Free in GitHub repository vim/vim prior to 9.0.0530. | |
| Modificada | Crítica (9.8) | 1.0% | — | Neoinfosys Nis-hap11ac Firmware | 19/9/2022 | 17/6/2026 | This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device. | |
| Analizada | Alta (7.8) | 0.56% | — | NeovimVIMDebian Linux | 6/9/2022 | 24/9/2026 | Use After Free in GitHub repository vim/vim prior to 9.0.0389. | |
| Analizada | Alta (7.8) | 0.53% | — | NeovimVIMFedoraproject Fedora | 30/8/2022 | 24/9/2026 | Use After Free in GitHub repository vim/vim prior to 9.0.0322. | |
| Modificada | Alta (7.5) | 1.4% | — | Neo4j Awesome Procedures ON Cypher | 12/8/2022 | 17/6/2026 | Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream. | |
| Modificada | Crítica (9.8) | 1.2% | — | Ceneo-web-scrapper Project Ceneo-web-scrapper | 11/7/2022 | 17/6/2026 | The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (8.8) | 0.34% | — | Douzone Neors | 28/6/2022 | 17/6/2026 | Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infections. | |
| Modificada | Media (5.4) | 0.59% | — | Neos CMS | 2/6/2022 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title. The vulnerabilities were found in versions 3.3.29 and 8.0.1 and could also be present in all… | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Simatic PCS NEOSiemens SinetplanSiemens Totally Integrated Automation Portal | 12/4/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process specially crafted packets sent to port 8888/tcp. A remote attacker could exploit this vulnerability to… | |
| Modificada | Alta (8.8) | 0.67% | — | Yubico Ykneo-openpgp | 30/3/2022 | 17/6/2026 | Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated. | |
| Modificada | Media (5.6) | 0.50% | — | XENARM Cortex-r7 FirmwareARM Cortex-r8 FirmwareARM Cortex-a57 Firmware+18 | 13/3/2022 | 17/6/2026 | Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive… | |
| Modificada | Media (4.7) | 0.30% | — | Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareARM Neoverse-e1 FirmwareARM Neoverse-v1 Firmware+18 | 10/3/2022 | 17/6/2026 | Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to… | |
| Modificada | Crítica (9.1) | 1.5% | — | Neo4j Awesome Procedures | 1/3/2022 | 17/6/2026 | A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1. | |
| Analizada | Alta (7.8) | 1.9% | — | NeovimVIMFedoraproject FedoraDebian Linux | 1/12/2021 | 17/6/2026 | vim is vulnerable to Heap-based Buffer Overflow | |
| Modificada | Alta (8.8) | 1.7% | — | Douzone Neors | 30/11/2021 | 17/6/2026 | The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX. | |
| Modificada | Alta (7.1) | 0.30% | — | Wibu Codemeter RuntimeSiemens PSS CapeSiemens PSS ESiemens PSS Odms+6 | 14/11/2021 | 17/6/2026 | In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions. | |
| Modificada | Crítica (9.8) | 1.6% | — | Neoan3-template | 8/11/2021 | 17/6/2026 | neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a method or function in scope and can… | |
| Modificada | Crítica (9.8) | 13% | 💥 PoC | Neo4j | 5/8/2021 | 17/6/2026 | Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies with exploitable gadget chains. | |
| Modificada | Alta (8.8) | 1.0% | — | Neo4j Graph Databse | 30/7/2021 | 17/6/2026 | A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges. | |
| Modificada | Media (5.3) | 1.1% | — | Neos Form | 21/6/2021 | 17/6/2026 | neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validators. Form state is secured with an HMAC that is still verified. That means that this issue can only be exploited if Form Finishers cause side… | |
| Modificada | Crítica (9.1) | 33% | — | Wibu CodemeterSiemens PSS CapeSiemens Sicam 230 FirmwareSiemens Simatic Information Server+6 | 16/6/2021 | 17/6/2026 | A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server. | |
| Modificada | Alta (8.8) | 0.44% | — | Samsung Galaxy Watch Active 2 FirmwareSamsung Galaxy Watch Active FirmwareSamsung Galaxy Watch FirmwareSamsung Galaxy Watch 3 Firmware+5 | 11/6/2021 | 17/6/2026 | Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness. | |
| Modificada | Media (5.4) | 0.62% | — | Neox Hana FLV Player | 24/5/2021 | 17/6/2026 | The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field. | |
| Modificada | Crítica (9.1) | 2.6% | — | MuttNeomutt | 5/5/2021 | 17/6/2026 | Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default. |