Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.81% | 💥 PoC | Wftpserver Wing FTP Server | 7/3/2020 | 17/6/2026 | Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files. | |
| Modificada | Alta (7.8) | 0.43% | — | Wftpserver Wing FTP Server | 7/3/2020 | 17/6/2026 | Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 7Microsoft Windows Server 2008Siemens Axiom Multix M FirmwareSiemens Axiom Vertix MD Trauma Firmware+63 | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.5) | 0.89% | — | Cmswing | 17/2/2019 | 17/6/2026 | global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing. | |
| Modificada | Alta (8.1) | 2.2% | — | Opendesign Drawings SDKOracle Outside IN Technology | 19/10/2018 | 17/6/2026 | A vulnerability exists in the file reading procedure in Open Design Alliance Drawings SDK 2019Update1 on non-Windows platforms in which attackers could perform read operations past the end, or before the beginning, of the intended buffer. This can allow attackers to obtain sensitive information from process memory or… | |
| Modificada | Alta (8.1) | 2.2% | — | Opendesign Drawings SDKOracle Outside IN Technology | 19/10/2018 | 17/6/2026 | Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash. | |
| Modificada | Alta (7.5) | 0.46% | — | Extremenetworks Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext credentials) by an attacker who has access to a wired port. | |
| Modificada | Alta (7.2) | 1.4% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Hidden Root Shell by entering the administrator password in conjunction with the 'service start-shell' CLI command. | |
| Modificada | Media (4.9) | 0.69% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is Arbitrary File Write from the WebGUI on the WiNG Access Point / Controller. | |
| Modificada | Media (5.3) | 0.81% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is No Authentication for the AeroScout Service via a crafted UDP packet. | |
| Modificada | Media (5.9) | 0.98% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Heap Overflow in the HSD Process over the MINT (Media Independent Tunnel) Protocol on the WiNG Access Point via crafted packets. | |
| Modificada | Media (5.9) | 0.98% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Heap Overflow in the HSD Process over the MINT (Media Independent Tunnel) Protocol on the WiNG Access Point via crafted packets. | |
| Modificada | Media (5.9) | 0.98% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Heap Overflow in the HSD Process over the MINT (Media Independent Tunnel) Protocol on the WiNG Access Point via crafted packets. | |
| Modificada | Media (5.3) | 0.43% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is Remote, Unauthenticated "Global" Denial of Service in the RIM (Radio Interface Module) over the MINT (Media Independent Tunnel) Protocol on the WiNG Access Point via crafted packets. | |
| Modificada | Alta (7.5) | 1.1% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated XML Entity Expansion Denial of Service on the WiNG Access Point / Controller via crafted XML entities to the Web User Interface. | |
| Modificada | Alta (7.5) | 1.3% | — | Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Denial of Service in the RIM (Radio Interface Module) process running on the WiNG Access Point via crafted packets. | |
| Modificada | Alta (7.5) | 1.3% | — | Extremenetworks Extremewireless Wing | 5/2/2018 | 17/6/2026 | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Stack Overflow in the RIM (Radio Interface Module) process running on the WiNG Access Point via crafted packets. | |
| Modificada | Media (6.8) | 2.4% | — | Wftpserver Wing FTP Server | 10/6/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to admin_lua_script.html or (2) add a domain administrator via a crafted request to… | |
| Modificada | Media (5.4) | 0.27% | — | Easy Tips FOR Glowing Skin Project Easy Tips FOR Glowing Skin | 20/10/2014 | 17/6/2026 | The Easy Tips For Glowing Skin (aka com.n.easytipsforglowingskin) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Germanwings | 16/10/2014 | 17/6/2026 | The Germanwings (aka com.germanwings.android) application 2.1.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 2.2% | — | Wftpserver Wing FTP Server | 26/10/2012 | 16/6/2026 | Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Pro-face Pro-server EXPro-face Wingp PC Runtime | 25/6/2012 | 16/6/2026 | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a… | |
| Modificada | Media (5) | 11% | 💥 Exploit | Pro-face Pro-server EXPro-face Wingp PC Runtime | 25/6/2012 | 16/6/2026 | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to obtain sensitive information from daemon memory via a crafted packet with a certain opcode. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Pro-face Pro-server EXPro-face Wingp PC Runtime | 25/6/2012 | 16/6/2026 | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode and a large value in a size field. | |
| Modificada | Media (5) | 21% | 💥 Exploit | Pro-face Pro-server EXPro-face Wingp PC Runtime | 25/6/2012 | 16/6/2026 | Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted packet with a certain opcode that triggers an invalid attempt to allocate a large amount of memory. |