Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Basic B2B Script Project Basic B2B Script | 13/12/2017 | 17/6/2026 | Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. | |
| Modificada | Media (6.1) | 2.2% | — | Phoenixcontact FL Comserver Basic 232 FirmwarePhoenixcontact FL Comserver UNI 422 FirmwarePhoenixcontact FL Comserver BAS 485-t FirmwarePhoenixcontact FL COM Server Rs232 Firmware+9 | 11/12/2017 | 17/6/2026 | A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The… | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Readymadeb2bscript Basic B2B Script | 31/10/2017 | 17/6/2026 | Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. | |
| Modificada | Alta (7.1) | 0.91% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+75 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected. | |
| Modificada | Alta (7.1) | 1.1% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+89 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected. | |
| Modificada | Media (4.3) | 33% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Office Word Viewer+10 | 17/3/2017 | 17/6/2026 | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site,… | |
| Modificada | Media (5.5) | 16% | 💥 Exploit | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Office Word Viewer+10 | 17/3/2017 | 17/6/2026 | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site,… | |
| Modificada | Alta (7.5) | 2.5% | — | Fidelex Fx-2030a FirmwareFidelex Fx-2030a-basic Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Fidelix FX-20 series controllers, versions prior to 11.50.19. Arbitrary file reading via path traversal allows an attacker to access arbitrary files and directories on the server. | |
| Modificada | Media (6.4) | 0.38% | — | Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic IT Production SuiteSiemens Simatic NET PC Software+14 | 15/11/2016 | 17/6/2026 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7… | |
| Modificada | Media (6.5) | 1.0% | — | Amazonbasics FirmwareDell Km714 FirmwareDell Km632 FirmwareLogitech Unifying Firmware+1 | 2/8/2016 | 17/6/2026 | The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity… | |
| Modificada | Crítica (9.8) | 25% | — | Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited | 14/5/2016 | 17/6/2026 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors. | |
| Modificada | Crítica (9.4) | 4.3% | — | Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited | 14/5/2016 | 17/6/2026 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature." | |
| Modificada | Crítica (9.4) | 64% | 💥 Exploit | Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited | 14/5/2016 | 17/6/2026 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors. | |
| Modificada | Media (4.3) | 11% | — | Microsoft ExcelMicrosoft OfficeMicrosoft PowerpointMicrosoft Visio+2 | 13/1/2016 | 17/6/2026 | Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013… | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+10 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and… | |
| Modificada | Alta (9.3) | 34% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+10 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and… | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+11 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before… | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+11 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before… | |
| Modificada | Alta (9.3) | 22% | — | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+11 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Silverlight… | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | Microsoft Live MeetingMicrosoft LyncMicrosoft Lync BasicMicrosoft Office | 15/8/2015 | 17/6/2026 | Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability." | |
| Modificada | Media (5) | 16% | 💥 Exploit | Intelligent-it Paypal Currency Converter Basic FOR Woocommerce | 24/6/2015 | 17/6/2026 | Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter. | |
| Modificada | Media (5) | 1.4% | — | Services Basic Authentication Project Services Basic Authentication | 15/6/2015 | 17/6/2026 | The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Basic-cms Sweetrice | 3/1/2015 | 16/6/2026 | The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail address in the email parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Basic-cms Sweetrice | 3/1/2015 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3) the sys-name parameter in an rssfeed action, or (4) the sys-name… | |
| Modificada | Media (4.3) | 0.97% | — | Basic-cms Sweetrice | 3/1/2015 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to inject arbitrary web script or HTML via a top_height cookie. |