Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Media (5.4) | 2.0% | 💥 Exploit | Ultimatekode NEO Billing | 2/3/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (6.5) | 6.4% | 💥 PoC | Yeastar Neogate Tg400 Firmware | 19/2/2021 | 9/7/2026 | Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key. | |
| Modificada | Alta (7.8) | 0.86% | — | Siemens Simatic Process Control System NEOSiemens Totally Integrated Automation Portal | 9/2/2021 | 17/6/2026 | A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid… | |
| Modificada | Media (4.2) | 0.20% | — | Ftsafe K13Ftsafe K21Ftsafe K40Ftsafe K9+41 | 7/1/2021 | 17/6/2026 | An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was… | |
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | Onlineonly Phpjabbers Appointment Scheduler | 15/12/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (6.1) | 0.78% | — | Desknets NEO | 3/12/2020 | 17/6/2026 | Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors. | |
| Modificada | Media (5.3) | 2.4% | — | MuttNeomuttDebian Linux | 23/11/2020 | 17/6/2026 | Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an… | |
| Modificada | Media (6.5) | 0.41% | — | Creativeitem Neoflex Video Subscription System | 4/11/2020 | 17/6/2026 | Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings) | |
| Modificada | Media (5.5) | 0.24% | — | Huawei Bla-a09 FirmwareHuawei Bla-tl00b FirmwareHuawei Berkeley-l09 FirmwareHuawei Duke-l09 Firmware+9 | 11/9/2020 | 17/6/2026 | Huawei smartphones BLA-A09 versions 8.0.0.123(C212),versions earlier than 8.0.0.123(C567),versions earlier than 8.0.0.123(C797);BLA-TL00B versions earlier than 8.1.0.326(C01);Berkeley-L09 versions earlier than 8.0.0.163(C10),versions earlier than 8.0.0.163(C432),Versions earlier than 8.0.0.163(C636),Versions earlier… | |
| Modificada | Media (5.4) | 0.55% | — | Laborator Neon | 27/8/2020 | 17/6/2026 | Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab. | |
| Modificada | Crítica (9.8) | 17% | 💥 Exploit | Inneo Startup Tools | 23/7/2020 | 17/6/2026 | An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via… | |
| Modificada | Media (5.3) | 2.2% | — | Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+9 | 14/7/2020 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS… | |
| Modificada | Alta (8.2) | 2.5% | — | Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+9 | 14/7/2020 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS… | |
| Modificada | Media (6.7) | 0.38% | — | Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+7 | 14/7/2020 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC Notifier… | |
| Modificada | Media (5.9) | 2.3% | — | MuttDebian LinuxNeomuttFedoraproject Fedora+2 | 21/6/2020 | 17/6/2026 | Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection." | |
| Modificada | Media (6.7) | 0.46% | — | Siemens Simatic Automatic ToolSiemens Simatic NET PCSiemens Simatic PCS 7Siemens Simatic PCS NEO+13 | 10/6/2020 | 17/6/2026 | A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All… | |
| Modificada | Media (5.4) | 0.55% | — | Laborator Neon | 6/6/2020 | 17/6/2026 | The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard. | |
| Modificada | Alta (7.8) | 1.0% | — | Hancom Office NEO | 19/3/2020 | 17/6/2026 | The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file. | |
| Modificada | Alta (7.8) | 1.1% | — | Hancom Office NEO | 19/3/2020 | 17/6/2026 | The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file. | |
| Modificada | Media (6.1) | 5.0% | 💥 Exploit | Laborator Neon | 30/12/2019 | 17/6/2026 | An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter. | |
| Modificada | Media (5.3) | 0.92% | — | Huawei Alp-al00b FirmwareHuawei Alp-tl00b FirmwareHuawei Bla-al00b FirmwareHuawei Bla-tl00b Firmware+46 | 14/12/2019 | 17/6/2026 | Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal. | |
| Modificada | Alta (7.8) | 0.31% | — | Samsung Galaxy J7 NEO Firmware | 14/11/2019 | 17/6/2026 | The Samsung J7 Neo Android device with a build fingerprint of samsung/j7velteub/j7velte:8.1.0/M1AJQ/J701MUBS6BSB4:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app… | |
| Modificada | Alta (7.8) | 0.31% | — | Samsung Galaxy J7 NEO Firmware | 14/11/2019 | 17/6/2026 | The Samsung J7 Neo Android device with a build fingerprint of samsung/j7veltedx/j7velte:8.1.0/M1AJQ/J701FXVS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app… | |
| Modificada | Alta (7.8) | 0.31% | — | Samsung Galaxy J7 NEO Firmware | 14/11/2019 | 17/6/2026 | The Samsung J7 Neo Android device with a build fingerprint of samsung/j7velteub/j7velte:8.1.0/M1AJQ/J701MUBS6BSB3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app… |