Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.84% | — | Jetbrains Scala | 21/2/2020 | 17/6/2026 | In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections. | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens DK Standard Ethernet ControllerSiemens Profinet DriverSiemens Simatic IPC SupportSiemens Ek-ertec 200 Firmware+48 | 11/2/2020 | 17/6/2026 | Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack.… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens Scalance S602 FirmwareSiemens Scalance S612 FirmwareSiemens Scalance S623 FirmwareSiemens Scalance S627-2m Firmware | 11/2/2020 | 17/6/2026 | A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port 443/tcp of affected devices could cause a… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens Scalance S602 FirmwareSiemens Scalance S612 FirmwareSiemens Scalance S623 FirmwareSiemens Scalance S627-2m Firmware | 11/2/2020 | 17/6/2026 | A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port 443/tcp of affected devices could cause a… | |
| Modificada | Media (5.4) | 0.83% | — | Siemens Scalance Xc-200 FirmwareSiemens Scalance Xf-200 FirmwareSiemens Scalance Xp-200 FirmwareSiemens Scalance X-200irt Firmware+4 | 11/2/2020 | 17/6/2026 | A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All versions < V4.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < 5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS… | |
| Modificada | Crítica (9.8) | 5.1% | — | Arubanetworks AirwaveArubanetworks Aruba InstantArubanetworks ArubaosSiemens Scalance W1750d Firmware | 31/1/2020 | 17/6/2026 | Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary… | |
| Modificada | Alta (8.6) | 1.4% | — | Siemens Scalance X-200rna FirmwareSiemens Scalance X204rna FirmwareSiemens Scalance X-300 FirmwareSiemens Scalance Xr-300wg Firmware+3 | 16/1/2020 | 17/6/2026 | A vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRP), SCALANCE X204RNA EEC (PRP/HSR), SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7… | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens DK Standard Ethernet Controller FirmwareSiemens Ek-ertec 200 Firmware+36 | 10/10/2019 | 17/6/2026 | An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation. | |
| Modificada | Alta (7.8) | 2.2% | — | Openbsd OpensshNetapp Cloud BackupNetapp Steelstore Cloud Integrated StorageSiemens Scalance X204rna Firmware+1 | 9/10/2019 | 17/6/2026 | OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the… | |
| Modificada | Alta (8.6) | 1.4% | — | Siemens Scalance X-200 FirmwareSiemens Scalance X-200irt FirmwareSiemens Scalance X-200rna Firmware | 13/8/2019 | 17/6/2026 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X204RNA (HSR) (All versions), SCALANCE X204RNA (PRP) (All versions), SCALANCE X204RNA EEC (HSR) (All… | |
| Modificada | Media (6.6) | 0.41% | — | Siemens Scalance Sc-600 Firmware | 13/8/2019 | 17/6/2026 | A vulnerability has been identified in SCALANCE SC-600 (V2.0). An authenticated attacker with access to port 22/tcp as well as physical access to an affected device may trigger the device to allow execution of arbitrary commands. The security vulnerability could be exploited by an authenticated attacker with physical… | |
| Modificada | Media (6.5) | 1.2% | — | Siemens Scalance Xb-200 FirmwareSiemens Scalance Xc-200 FirmwareSiemens Scalance Xf-200ba FirmwareSiemens Scalance Xp-200 Firmware+1 | 13/8/2019 | 17/6/2026 | A vulnerability has been identified in SCALANCE SC-600 (V2.0), SCALANCE XB-200 (V4.1), SCALANCE XC-200 (V4.1), SCALANCE XF-200BA (V4.1), SCALANCE XP-200 (V4.1), SCALANCE XR-300WG (V4.1). An authenticated attacker with network access to to port 22/tcp of an affected device may cause a Denial-of-Service condition. The… | |
| Modificada | Media (5.5) | 0.30% | — | Siemens Scalance X-200 FirmwareSiemens Scalance X-200irt FirmwareSiemens Scalance X-300 FirmwareSiemens Scalance X-414-3e Firmware | 12/6/2019 | 17/6/2026 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X-414-3E (All… | |
| Modificada | Crítica (9.8) | 4.6% | — | Arubanetworks Aruba InstantSiemens Scalance W1750d Firmware | 10/5/2019 | 17/6/2026 | A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the… | |
| Modificada | Media (6.1) | 1.4% | — | Arubanetworks Aruba InstantSiemens Scalance W1750d Firmware | 10/5/2019 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an… | |
| Modificada | Alta (7.5) | 1.8% | — | Arubanetworks Aruba InstantSiemens Scalance W1750d Firmware | 10/5/2019 | 17/6/2026 | If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that unauthenticated users can access them through the Aruba Instant web interface. Core dumps could… | |
| Modificada | Alta (7.2) | 4.3% | — | Arubanetworks Aruba InstantSiemens Scalance W1750d Firmware | 10/5/2019 | 17/6/2026 | A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged.… | |
| Modificada | Crítica (9.1) | 1.3% | — | Siemens Scalance X-200 FirmwareSiemens Scalance X-300 FirmwareSiemens Scalance Xp-200 FirmwareSiemens Scalance Xc-200 Firmware+1 | 26/3/2019 | 17/6/2026 | The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior. | |
| Modificada | Media (5.9) | 58% | 💥 Exploit | Openbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+15 | 31/1/2019 | 17/6/2026 | An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp… | |
| Modificada | Media (6.8) | 21% | 💥 Exploit | Openbsd OpensshWinscpNetapp Element SoftwareNetapp Ontap Select Deploy+3 | 31/1/2019 | 17/6/2026 | In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred. | |
| Modificada | Media (6.8) | 3.8% | — | Openbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+16 | 31/1/2019 | 17/6/2026 | An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects… | |
| Modificada | Media (5.3) | 3.7% | — | Openbsd OpensshWinscpNetapp Cloud BackupNetapp Element Software+18 | 10/1/2019 | 17/6/2026 | In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. | |
| Modificada | Media (5.4) | 0.69% | — | Siemens Scalance S602 FirmwareSiemens Scalance S612 FirmwareSiemens Scalance S623 FirmwareSiemens Scalance S627-2m Firmware | 13/12/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into… | |
| Modificada | Media (5.5) | 0.81% | — | Scalabium Dbf2txt | 14/9/2018 | 17/6/2026 | An issue has been found in dbf2txt through 2012-07-19. It is a infinite loop. | |
| Modificada | Alta (8.6) | 4.2% | — | Siemens Scalance X408 FirmwareSiemens Scalance X300 FirmwareSiemens Scalance X414 Firmware | 12/9/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). The web interface on port 443/tcp could allow an attacker to cause a Denial-of-Service condition by sending specially crafted packets to the web server. The device will… |