Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Siemens Sinema Remote Connect Client | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an administrative remote attacker running a… | |
| Modificada | Alta (8.5) | 0.90% | — | Siemens Sinema Remote Connect Client | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading proxy configurations. This could allow an authenticated local attacker to execute… | |
| Analizada | Alta (8.5) | 0.90% | — | Siemens Sinema Remote Connect Client | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an authenticated local attacker to execute… | |
| Analizada | Alta (7.2) | 0.79% | — | Devolutions Remote Desktop Manager | 26/6/2024 | 17/6/2026 | Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard. | |
| Analizada | Crítica (9.8) | 0.92% | — | Devolutions Remote Desktop Manager | 17/6/2024 | 17/6/2026 | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature. | |
| Analizada | Media (4.7) | 0.50% | — | Devolutions Remote Desktop Manager | 17/6/2024 | 17/6/2026 | Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file. | |
| Aplazada | Crítica (9.8) | 1.6% | — | Toshibatec Remote Command ProgramAI | 14/6/2024 | 17/6/2026 | Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on… | |
| Aplazada | Crítica (9.8) | 3.2% | 💥 PoC | Toshibatec Remote CommandAI | 14/6/2024 | 17/6/2026 | Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score… | |
| Aplazada | Media (5.4) | 0.27% | — | Doublesharp Remote Content ShortcodeAI | 30/5/2024 | 17/6/2026 | The Remote Content Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'remote_content' shortcode in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Aplazada | Media (6.5) | 0.59% | — | Doublesharp Remote Content ShortcodeAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Justin Silver Remote Content Shortcode allows PHP Local File Inclusion.This issue affects Remote Content Shortcode: from n/a through 1.5. | |
| Aplazada | Alta (7) | 0.27% | 💥 PoC | Rockwellautomation Factorytalk Remote AccessAI | 16/5/2024 | 17/6/2026 | An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a… | |
| Aplazada | Alta (7.6) | 0.25% | — | DPS Telecom Netguardian DIN Remote Telemetry UnitAI | 30/4/2024 | 17/6/2026 | Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential, Cross Site Scripting (XSS) and Cross-Site… | |
| Analizada | Media (4.3) | 0.28% | — | Devolutions ServerDevolutions Remote Desktop Manager | 9/4/2024 | 17/6/2026 | Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software… | |
| Aplazada | Alta (7.1) | 0.21% | — | Teamviewer Remote ClientAI | 26/3/2024 | 17/6/2026 | Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges or conduct a denial-of-service-attack by overwriting the symlink. | |
| Analizada | Media (5.9) | 0.42% | — | Devolutions Remote Desktop Manager | 13/3/2024 | 17/6/2026 | Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary directory. | |
| Modificada | Media (6.5) | 0.43% | — | Siemens Sinema Remote Connect Client | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This information is also available via the… | |
| Modificada | Crítica (9.8) | 0.84% | — | Siemens Sinema Remote Connect Server | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to code execution. | |
| Analizada | Alta (7.8) | 0.20% | — | Teamviewer Remote | 27/2/2024 | 17/6/2026 | Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges by changing the personal password setting and establishing a remote connection to a logged-in admin account. | |
| Modificada | Media (5.4) | 0.29% | — | Devolutions Remote Desktop Manager | 31/1/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry. | |
| Modificada | Media (5.3) | 0.53% | — | Openlibraryfoundation Mod-remote-storage | 19/1/2024 | 14/7/2026 | Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types. | |
| Modificada | Crítica (9.8) | 1.1% | — | Unifiedremote Unified Remote | 30/12/2023 | 17/6/2026 | Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload endpoint. | |
| Modificada | Media (5.4) | 0.33% | — | Brainstormforce WP Remote Site Search | 29/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force WP Remote Site Search allows Stored XSS.This issue affects WP Remote Site Search: from n/a through 1.0.4. | |
| Modificada | Media (4.4) | 0.17% | — | Devolutions Remote Desktop Manager | 21/12/2023 | 17/6/2026 | Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. This affects only SQL data sources. | |
| Modificada | Crítica (10) | 1.2% | — | Parallels Remote Application Server | 14/12/2023 | 17/6/2026 | The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques. | |
| Modificada | Crítica (9.8) | 0.73% | — | Devolutions Remote Desktop Manager | 12/12/2023 | 17/6/2026 | Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction. |