Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 32% | — | Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+47 | 6/9/2018 | 17/6/2026 | The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered… | |
| Modificada | Media (5.3) | 99% | 💥 Exploit | Openbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+18 | 17/8/2018 | 17/6/2026 | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c. | |
| Modificada | Media (4.9) | 1.9% | — | Siemens Scalance M875 Firmware | 26/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the web interface (443/tcp), could potentially read and download arbitrary files from the device's file system. Successful exploitation requires that the attacker has network access to the web… | |
| Modificada | Alta (7.2) | 3.7% | — | Siemens Scalance M875 Firmware | 26/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the web interface (443/tcp), could execute arbitrary operating system commands. Successful exploitation requires that the attacker has network access to the web interface. The attacker must be… | |
| Modificada | Alta (7.2) | 3.7% | — | Siemens Scalance M875 Firmware | 26/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the web interface (443/tcp), could execute arbitrary operating system commands. Successful exploitation requires that the attacker has network access to the web interface. The attacker must be… | |
| Modificada | Alta (7.8) | 0.42% | — | Siemens Scalance M875 Firmware | 26/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires read access to files on the local file system. A successful attack could allow an attacker to obtain administrative… | |
| Modificada | Media (4.8) | 0.32% | — | Siemens Scalance M875 Firmware | 26/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a stored Cross-Site Scripting (XSS) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires that the attacker has access to the web interface of an… | |
| Modificada | Alta (8.8) | 0.58% | — | Siemens Scalance M875 Firmware | 26/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by an legitimate user, who must be… | |
| Modificada | Media (6.1) | 1.0% | — | Siemens Scalance X300 FirmwareSiemens Scalance X-200 IRT FirmwareSiemens Scalance X-200 Firmware | 14/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET… | |
| Modificada | Media (4.8) | 0.83% | — | Siemens Scalance X200irt FirmwareSiemens Scalance X300 FirmwareSiemens Scalance X200 Firmware | 14/6/2018 | 17/6/2026 | A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). A remote, authenticated attacker with access to… | |
| Modificada | Alta (8.8) | 0.95% | — | Siemens Rfid 181-eip FirmwareSiemens Ruggedcom Wimax FirmwareSiemens Scalance X200 FirmwareSiemens Scalance X200irt Firmware+5 | 14/6/2018 | 17/6/2026 | A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All… | |
| Modificada | Alta (8.1) | 1.8% | — | Scalajs-standalone-bin Project Scalajs-standalone-bin | 1/6/2018 | 17/6/2026 | scala-standalone-bin is a Binary wrapper for ScalaJS. scala-standalone-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network… | |
| Modificada | Alta (8.1) | 1.7% | — | Scala-bin Project Scala-bin | 29/5/2018 | 17/6/2026 | scala-bin is a binary wrapper for Scala. scala-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between… | |
| Modificada | Alta (8.8) | 1.1% | — | Siemens Scalance Xb-200 FirmwareSiemens Scalance Xc-200 FirmwareSiemens Scalance Xp-200 FirmwareSiemens Scalance Xr300-wg Firmware+3 | 26/12/2017 | 17/6/2026 | After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions. | |
| Modificada | Media (5.9) | 25% | — | WolfsslSiemens Scalance W1750d FirmwareArubanetworks Instant | 13/12/2017 | 17/6/2026 | wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL application. This vulnerability is referred to as "ROBOT." | |
| Modificada | Alta (7.8) | 0.35% | — | Scala-lang Scala | 15/11/2017 | 17/6/2026 | The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges. | |
| Modificada | Media (5.3) | 0.58% | — | Really Jwt-scala | 12/10/2017 | 17/6/2026 | jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Thekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+17 | 4/10/2017 | 17/6/2026 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | |
| Modificada | Alta (7.1) | 0.91% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+75 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected. | |
| Modificada | Alta (7.1) | 1.1% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+89 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected. | |
| Modificada | Media (4) | 1.9% | — | Siemens Scalance M-800 FirmwareSiemens Scalance S615 Firmware | 29/9/2016 | 17/6/2026 | The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | |
| Modificada | Media (5.3) | 8.6% | 💥 Exploit | Siemens Scalance S613 | 8/4/2016 | 17/6/2026 | Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443. | |
| Modificada | Media (6.8) | 1.7% | — | Siemens Scalance X-200 Series Firmware | 2/2/2015 | 17/6/2026 | The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors. | |
| Modificada | Media (6.8) | 1.5% | — | Siemens Scalance X-408 FirmwareSiemens Scalance X-300 Series Firmware | 21/1/2015 | 17/6/2026 | The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP packets. | |
| Modificada | Alta (7.8) | 2.2% | — | Siemens Scalance X-300 Series FirmwareSiemens Scalance X-408 Firmware | 21/1/2015 | 17/6/2026 | The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote attackers to cause a denial of service (reboot) via malformed HTTP requests. |