Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)0.45%—Velneo Vclient23/9/202217/6/2026
Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has access to the network to perform a MITM attack in order to obtain the user´s credentials.
AnalizadaAlta (7.8)0.49%—NeovimVIMFedoraproject FedoraDebian Linux22/9/202224/9/2026
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
ModificadaCrítica (9.8)1.0%—Neoinfosys Nis-hap11ac Firmware19/9/202217/6/2026
This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.
AnalizadaAlta (7.8)0.56%—NeovimVIMDebian Linux6/9/202224/9/2026
Use After Free in GitHub repository vim/vim prior to 9.0.0389.
AnalizadaAlta (7.8)0.53%—NeovimVIMFedoraproject Fedora30/8/202224/9/2026
Use After Free in GitHub repository vim/vim prior to 9.0.0322.
ModificadaAlta (7.5)1.4%—Neo4j Awesome Procedures ON Cypher12/8/202217/6/2026
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.
ModificadaCrítica (9.8)1.2%—Ceneo-web-scrapper Project Ceneo-web-scrapper11/7/202217/6/2026
The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (8.8)0.34%—Douzone Neors28/6/202217/6/2026
Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infections.
ModificadaMedia (5.4)0.59%—Neos CMS2/6/202217/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title. The vulnerabilities were found in versions 3.3.29 and 8.0.1 and could also be present in all…
ModificadaAlta (7.5)1.4%—Siemens Simatic PCS NEOSiemens SinetplanSiemens Totally Integrated Automation Portal12/4/202217/6/2026
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process specially crafted packets sent to port 8888/tcp. A remote attacker could exploit this vulnerability to…
ModificadaAlta (8.8)0.67%—Yubico Ykneo-openpgp30/3/202217/6/2026
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
ModificadaMedia (5.6)0.50%—XENARM Cortex-r7 FirmwareARM Cortex-r8 FirmwareARM Cortex-a57 Firmware+1813/3/202217/6/2026
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive…
ModificadaMedia (4.7)0.30%—Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareARM Neoverse-e1 FirmwareARM Neoverse-v1 Firmware+1810/3/202217/6/2026
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to…
ModificadaCrítica (9.1)1.5%—Neo4j Awesome Procedures1/3/202217/6/2026
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.
AnalizadaAlta (7.8)1.9%—NeovimVIMFedoraproject FedoraDebian Linux1/12/202117/6/2026
vim is vulnerable to Heap-based Buffer Overflow
ModificadaAlta (8.8)1.7%—Douzone Neors30/11/202117/6/2026
The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.
ModificadaAlta (7.1)0.30%—Wibu Codemeter RuntimeSiemens PSS CapeSiemens PSS ESiemens PSS Odms+614/11/202117/6/2026
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
ModificadaCrítica (9.8)1.6%—Neoan3-template8/11/202117/6/2026
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a method or function in scope and can…
ModificadaCrítica (9.8)13%💥 PoCNeo4j5/8/202117/6/2026
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies with exploitable gadget chains.
ModificadaAlta (8.8)1.0%—Neo4j Graph Databse30/7/202117/6/2026
A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges.
ModificadaMedia (5.3)1.1%—Neos Form21/6/202117/6/2026
neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validators. Form state is secured with an HMAC that is still verified. That means that this issue can only be exploited if Form Finishers cause side…
ModificadaCrítica (9.1)33%—Wibu CodemeterSiemens PSS CapeSiemens Sicam 230 FirmwareSiemens Simatic Information Server+616/6/202117/6/2026
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
ModificadaAlta (8.8)0.44%—Samsung Galaxy Watch Active 2 FirmwareSamsung Galaxy Watch Active FirmwareSamsung Galaxy Watch FirmwareSamsung Galaxy Watch 3 Firmware+511/6/202117/6/2026
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.
ModificadaMedia (5.4)0.62%—Neox Hana FLV Player24/5/202117/6/2026
The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.
ModificadaCrítica (9.1)2.6%—MuttNeomutt5/5/202117/6/2026
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which imap/util.c has an out-of-bounds read in situations where an IMAP sequence set ends with a comma. NOTE: the $imap_qresync setting for QRESYNC is not enabled by default.
Orbitaley — Vulnerabilidades