Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

3363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.7)0.39%—Nvidia Connectx Firmware22/4/202317/6/2026
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can cause improper handling of exceptional conditions, which may lead to denial of service.
ModificadaAlta (7.7)0.52%—Nvidia Connectx Firmware22/4/202317/6/2026
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.
ModificadaMedia (5.3)1.3%💥 PoCOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core PolicyOracle Mysql ConnectorsNetapp Active IQ Unified Manager+218/4/202317/6/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require…
ModificadaMedia (5.7)0.38%—Uniswap Web3-react Coinbase-walletUniswap Web3-react Eip1193Uniswap Web3-react MetamaskUniswap Web3-react Walletconnect17/4/202317/6/2026
@web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may be incorrect. In an application, this means that any data derived from `chainId`…
ModificadaAlta (7.5)0.98%—Microsoft Azure Service Connector11/4/202317/6/2026
Azure Service Connector Security Feature Bypass Vulnerability
ModificadaMedia (4.8)0.39%—E4jconnect Vikrentcar6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikRentCar Car Rental Management System plugin <= 1.3.0 versions.
ModificadaCrítica (9.8)0.66%—IBM Aspera CargoIBM Aspera Connect2/4/202317/6/2026
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.
ModificadaCrítica (9.8)0.66%—IBM Aspera CargoIBM Aspera Connect2/4/202317/6/2026
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.
ModificadaAlta (7.5)0.35%—Forgerock Ldap Connector29/3/202317/6/2026
Cleartext Transmission of Sensitive Information vulnerability in ForgeRock Inc. OpenIDM and Java Remote Connector Server (RCS) LDAP Connector on Windows, MacOS, Linux allows Remote Services with Stolen Credentials.This issue affects OpenIDM and Java Remote Connector Server (RCS): from 1.5.20.9 through 1.5.20.13.
ModificadaCrítica (9.1)3.4%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+429/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation…
ModificadaCrítica (9.8)3.4%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+429/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation…
ModificadaAlta (7.8)0.93%—Bentley Microstation Connect28/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
ModificadaAlta (8.8)1.0%—GFI Kerio Connect15/3/202317/6/2026
An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0). There is a stack-based Buffer Overflow in the webmail component's 2FASetup function via an authenticated request with a long primaryEMailAddress field to the webmail/api/jsonrpc URI.
ModificadaMedia (6.1)0.39%—IBM APP Connect Enterprise Certified Container15/3/202317/6/2026
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
ModificadaCrítica (9.8)0.60%—Accruent Maintenance Connection2/3/20239/7/2026
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.
ModificadaMedia (6.1)0.34%—Sophos Connect1/3/202317/6/2026
Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.
ModificadaMedia (5.5)0.13%—Sophos Connect1/3/202317/6/2026
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
ModificadaMedia (4.3)0.34%—Sophos Connect1/3/202317/6/2026
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
ModificadaCrítica (9.8)12%—GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+523/2/202317/6/2026
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
ModificadaCrítica (9.8)2.9%—GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+523/2/202317/6/2026
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.
ModificadaMedia (5.4)0.39%—Tibco Businessconnect22/2/202317/6/2026
The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are…
ModificadaMedia (5.4)0.40%—Tibco Businessconnect22/2/202317/6/2026
The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a cross-site scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO…
ModificadaMedia (5.3)83%💥 ExploitAdobe Connect17/2/202317/6/2026
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user…
ModificadaAlta (8.8)0.72%—Krontech Single Connect17/2/202317/6/2026
La validación de entrada inadecuada y la omisión de autorización a través de una vulnerabilidad de clave controlada por el usuario en Single Connect de Kron Tech en Windows permiten el abuso de privilegios. Este problema afecta a Single Connect: 2.16.
ModificadaMedia (5.9)0.42%—Dell Secure Connect Gateway17/2/202317/6/2026
Dell Secure Connect Gateway (SCG) versión 5.14.00.12 contiene una vulnerabilidad de algoritmo criptográfico roto. Un atacante remoto no autenticado podría explotar esta vulnerabilidad realizando ataques MitM y permitiendo que los atacantes obtengan información confidencial.