Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

352 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.9%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.5%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
ModificadaCrítica (9.8)3.8%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.2%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk…
ModificadaBaja (2.4)0.31%—Nextcloud Talk8/3/202217/6/2026
Nextcloud talk is a self hosting messaging service. In versions prior to 12.3.0 the Nextcloud Android Talk application did not properly detect the lockscreen state when a call was incoming. If an attacker got physical access to the locked phone, and the victim received a phone call the attacker could gain access to…
ModificadaMedia (6.1)1.0%—Nextcloud Talk8/3/202217/6/2026
Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user interaction. This only affected users of the…
ModificadaAlta (7.8)0.16%—Rockwellautomation Factorytalk View24/2/202217/6/2026
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the…
ModificadaMedia (5.5)0.27%—Rockwellautomation Factorytalk View24/2/202217/6/2026
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
ModificadaAlta (7.1)0.34%—Rockwellautomation Factorytalk Services Platform24/2/202217/6/2026
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.
ModificadaAlta (7.5)39%💥 ExploitSolari Termtalk Server15/2/202217/6/2026
A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download (http://url:port/file?valore).
ModificadaMedia (5.4)0.64%—Beanstalk Console Project Beanstalk Console9/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist ptrofimov/beanstalk_console prior to 1.7.14.
ModificadaMedia (6.1)0.87%—Beanstalk Console Project Beanstalk Console5/2/202217/6/2026
Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12.
ModificadaCrítica (9.8)2.5%—Talkyard3/1/202217/6/2026
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain…
ModificadaAlta (7.4)2.9%—Microsoft Biztalk ESB Toolkit15/12/202117/6/2026
Microsoft BizTalk ESB Toolkit Spoofing Vulnerability
ModificadaMedia (6.1)1.1%—Nextcloud Talk15/11/202117/6/2026
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file in a new tab. Due the strict Content-Security-Policy shipped with…
ModificadaAlta (8.8)1.3%—Talkyard11/11/202117/6/2026
In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection. By luring a victim application-user to click on a link, an unauthenticated…
ModificadaAlta (8.8)1.0%—UI Unifi Talk23/9/202117/6/2026
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk application V1.12.5 and later.
ModificadaMedia (6.5)1.0%—Nextcloud Talk12/7/202117/6/2026
Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier used username, they could get access to any chat message sent to the previous user with this username. The issue was patched in versions 11.2.2 and 11.3.0. As a…
ModificadaAlta (7.8)0.86%—Hmtalk Daviewindy12/7/202117/6/2026
DaviewIndy v8.98.7.0 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed format file that is mishandled by DaviewIndy. Attackers could exploit this and arbitrary code execution.
ModificadaAlta (7.5)2.3%—Voxmedia Coral Talk30/6/202117/6/2026
Talk 4 in Coral before 4.12.1 allows remote attackers to discover e-mail addresses and other sensitive information via GraphQL because permission checks use an incorrect data type.
ModificadaMedia (6.5)0.95%—Nextcloud Talk16/6/202117/6/2026
Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk App is upgraded to 9.0.10, 10.0.8 or…
ModificadaAlta (8.8)2.3%—Synology Diskstation ManagerDebian LinuxNetatalk21/5/202117/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exists within the processing of DSI structures in Netatalk. The issue results from the lack of proper…
ModificadaAlta (7.5)4.7%💥 ExploitCleantalk Spam Protection, Antispam, Firewall17/5/202117/6/2026
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent…
ModificadaAlta (7.8)0.93%—Hmtalk Daviewindy24/3/202117/6/2026
DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
ModificadaCrítica (10)4.2%—Rockwellautomation Factorytalk Services Platform18/3/202117/6/2026
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.