Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
838 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.40% | — | Openquantumsafe Liboqs | 6/12/2024 | 17/6/2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the HQC key encapsulation mechanism. Due to an indexing error, part of the secret key is incorrectly treated as non-secret data.… | |
| Aplazada | Alta (7) | 0.22% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+7 | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 5), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP… | |
| Analizada | Media (4.8) | 0.31% | — | 10up Safe SVG | 7/11/2024 | 17/6/2026 | The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data. | |
| Analizada | Media (5.9) | 0.19% | — | Google Safearchive | 4/11/2024 | 17/6/2026 | There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc | |
| Analizada | Media (5.3) | 5.3% | — | Esafenet CDG | 1/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the argument hookId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.58% | — | Esafenet CDG | 1/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/document/CDGAuthoriseTempletService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.3) | 0.57% | — | Esafenet CDG | 1/11/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/system/SystemEncryptPolicyService.java. The manipulation of the argument id leads to sql injection. The attack can be launched remotely.… | |
| Analizada | Media (5.3) | 0.57% | — | Esafenet CDG | 1/11/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInvalidCourse of the file /com/esafenet/servlet/system/HookInvalidCourseService.java. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (5.3) | 0.57% | — | Esafenet CDG | 1/11/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of the file /com/esafenet/servlet/system/PrintScreenListService.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.53% | — | Esafenet CDG | 1/11/2024 | 17/6/2026 | A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.60% | — | Esafenet CDG | 31/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Esafenet CDG | 31/10/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEntryptPolicySort of the file /com/esafenet/servlet/system/EncryptPolicyTypeService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (5.3) | 0.56% | — | Esafenet CDG | 31/10/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/PublicDocInfoAjax.java. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Esafenet CDG | 31/10/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument fileId leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Baja (3.7) | 0.47% | — | ARM Compiler FOR EmbeddedARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Clang | 31/10/2024 | 17/6/2026 | When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an… | |
| Analizada | Media (5.3) | 0.57% | — | Esafenet CDG | 30/10/2024 | 17/6/2026 | A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function getOneFileDirectory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument directoryId leads to sql injection. The attack can be initiated remotely.… | |
| Analizada | Media (5.3) | 0.57% | — | Esafenet CDG | 30/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function findById of the file /com/esafenet/servlet/document/ExamCDGDocService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Esafenet CDG | 30/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService.java. The manipulation of the argument policyId leads to sql injection. The attack may be launched remotely. The vendor… | |
| Analizada | Media (6.3) | 0.36% | — | Esafenet CDG | 25/10/2024 | 17/6/2026 | A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page. | |
| Analizada | Media (5.3) | 0.69% | — | Esafenet CDG | 25/10/2024 | 17/6/2026 | A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument decryptFileId with the input ../../../Windows/System32/drivers/etc/hosts… | |
| Analizada | Media (5.3) | 0.52% | — | Esafenet CDG | 25/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in ESAFENET CDG 5. Affected is the function actionViewCDGRenewFile of the file /com/esafenet/servlet/client/CDGRenewApplicationService.java. The manipulation of the argument CDGRenewFileId leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.3) | 0.71% | — | Esafenet CDG | 25/10/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. This issue affects the function actionPassDecryptApplication1 of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.76% | — | Esafenet CDG | 25/10/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function actionPassOrNotAutoSign of the file /com/esafenet/servlet/service/processsign/AutoSignService.java. The manipulation of the argument UniqueId leads to sql injection. The attack can be initiated… | |
| Aplazada | Media (5.3) | 0.15% | — | Oneidentity Safeguard FOR Privileged SessionsAI | 24/10/2024 | 17/6/2026 | An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise before 7.5.1 (and LTS before 7.0.5.1) allows man-in-the-middle attackers to obtain access to privileged sessions on target resources by intercepting cleartext RDP protocol information. | |
| Analizada | Media (5.3) | 0.60% | — | Esafenet CDG | 23/10/2024 | 17/6/2026 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects unknown code of the file /com/esafenet/servlet/policy/PrintPolicyService.java. The manipulation of the argument policyId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… |