Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using said function do not handle the exception. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to… | |
| Modificada | Crítica (9.8) | 1.9% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and… | |
| Modificada | Alta (7.5) | 1.7% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to shut down a specific… | |
| Modificada | Alta (7.5) | 2.5% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remote unauthenticated attacker to obtain file system read access via web server.. | |
| Modificada | Media (5.3) | 0.91% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specific service. | |
| Modificada | Crítica (9.8) | 4.1% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code… | |
| Modificada | Alta (8.8) | 1.8% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system. | |
| Modificada | Crítica (9.8) | 3.8% | — | Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control | 6/8/2020 | 17/6/2026 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet. | |
| Modificada | Alta (7.8) | 0.51% | — | QemuDebian LinuxNovell Open Desktop ServerNovell Open Enterprise Server | 30/12/2019 | 16/6/2026 | A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus… | |
| Modificada | Media (5.9) | 0.73% | — | Redhat Enterprise VirtualizationRedhat VdsclientRedhat Virtual Desktop Server Manager | 13/11/2019 | 17/6/2026 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack | |
| Modificada | Media (5.5) | 0.42% | — | Redhat Virtual Desktop Server ManagerRedhat Enterprise VirtualizationRedhat Storage | 4/11/2019 | 16/6/2026 | Insecure temporary file vulnerability in RedHat vsdm 4.9.6. | |
| Modificada | Baja (1.9) | 0.30% | — | Citrix Desktop ServerCitrix Presentation Server | 17/11/2008 | 16/6/2026 | The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files. | |
| Modificada | Media (6.5) | 1.4% | — | Citrix Access EssentialsCitrix Presentation ServerCitrix Desktop ServerCitrix Metaframe Presentation Server | 18/5/2008 | 16/6/2026 | Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allows remote authenticated users to access unauthorized desktops via unknown attack vectors. | |
| Modificada | Media (5) | 1.1% | — | Citrix Presentation ServerCitrix Access EssentialsCitrix Desktop Server | 18/5/2008 | 16/6/2026 | Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, which might allow attackers to bypass intended restrictions. | |
| Modificada | Alta (10) | 73% | — | Citrix Access EssentialsCitrix Desktop ServerCitrix Metaframe Presentation ServerCitrix Presentation Server | 18/1/2008 | 16/6/2026 | Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or… |