Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using said function do not handle the exception. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to… | |
| Modificada | Crítica (9.8) | 1.9% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and… | |
| Modificada | Alta (7.5) | 1.7% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to shut down a specific… | |
| Modificada | Alta (7.5) | 2.5% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remote unauthenticated attacker to obtain file system read access via web server.. | |
| Modificada | Media (5.3) | 0.91% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specific service. | |
| Modificada | Crítica (9.8) | 4.1% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code… | |
| Modificada | Alta (8.8) | 1.8% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system. | |
| Modificada | Media (5.5) | 0.34% | — | Eracent EDA AgentEracent EPA AgentEracent EPM AgentEracent EUA Agent+2 | 22/11/2019 | 17/6/2026 | An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following. |