Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

707 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Siemens Sinema Remote Connect Client9/7/202417/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an administrative remote attacker running a…
ModificadaAlta (8.5)0.90%—Siemens Sinema Remote Connect Client9/7/202417/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading proxy configurations. This could allow an authenticated local attacker to execute…
AnalizadaAlta (8.5)0.90%—Siemens Sinema Remote Connect Client9/7/202417/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an authenticated local attacker to execute…
AnalizadaAlta (7.2)0.79%—Devolutions Remote Desktop Manager26/6/202417/6/2026
Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.
AnalizadaCrítica (9.8)0.92%—Devolutions Remote Desktop Manager17/6/202417/6/2026
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature.
AnalizadaMedia (4.7)0.50%—Devolutions Remote Desktop Manager17/6/202417/6/2026
Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file.
AplazadaCrítica (9.8)1.6%—Toshibatec Remote Command ProgramAI14/6/202417/6/2026
Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on…
AplazadaCrítica (9.8)3.2%💥 PoCToshibatec Remote CommandAI14/6/202417/6/2026
Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score…
AplazadaMedia (5.4)0.27%—Doublesharp Remote Content ShortcodeAI30/5/202417/6/2026
The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
AplazadaMedia (6.5)0.59%—Doublesharp Remote Content ShortcodeAI17/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Justin Silver Remote Content Shortcode allows PHP Local File Inclusion.This issue affects Remote Content Shortcode: from n/a through 1.5.
AplazadaAlta (7)0.27%💥 PoCRockwellautomation Factorytalk Remote AccessAI16/5/202417/6/2026
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a…
AplazadaAlta (7.6)0.25%—DPS Telecom Netguardian DIN Remote Telemetry UnitAI30/4/202417/6/2026
Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential, Cross Site Scripting (XSS) and Cross-Site…
AnalizadaMedia (4.3)0.28%—Devolutions ServerDevolutions Remote Desktop Manager9/4/202417/6/2026
Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software…
AplazadaAlta (7.1)0.21%—Teamviewer Remote ClientAI26/3/202417/6/2026
Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges or conduct a denial-of-service-attack by overwriting the symlink.
AnalizadaMedia (5.9)0.42%—Devolutions Remote Desktop Manager13/3/202417/6/2026
Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary directory.
ModificadaMedia (6.5)0.43%—Siemens Sinema Remote Connect Client12/3/202417/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This information is also available via the…
ModificadaCrítica (9.8)0.84%—Siemens Sinema Remote Connect Server12/3/202417/6/2026
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to code execution.
AnalizadaAlta (7.8)0.20%—Teamviewer Remote27/2/202417/6/2026
Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges by changing the personal password setting and establishing a remote connection to a logged-in admin account.
ModificadaMedia (5.4)0.29%—Devolutions Remote Desktop Manager31/1/202417/6/2026
Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.
ModificadaMedia (5.3)0.53%—Openlibraryfoundation Mod-remote-storage19/1/202414/7/2026
Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.
ModificadaCrítica (9.8)1.1%—Unifiedremote Unified Remote30/12/202317/6/2026
Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint.
ModificadaMedia (5.4)0.33%—Brainstormforce WP Remote Site Search29/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force WP Remote Site Search allows Stored XSS.This issue affects WP Remote Site Search: from n/a through 1.0.4.
ModificadaMedia (4.4)0.17%—Devolutions Remote Desktop Manager21/12/202317/6/2026
Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. This affects only SQL data sources.
ModificadaCrítica (10)1.2%—Parallels Remote Application Server14/12/202317/6/2026
The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.
ModificadaCrítica (9.8)0.73%—Devolutions Remote Desktop Manager12/12/202317/6/2026
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.
Orbitaley — Vulnerabilidades