Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.62%—Siemens License ServerAI11/8/202628/8/2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.
Pendiente de análisisAlta (8.3)0.17%—Siemens License ServerAI11/8/202628/8/2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system…
AnalizadaCrítica (10)0.98%—HPE Autopass License Server2/3/202610/8/2026
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
AnalizadaCrítica (9.8)0.44%—HPE Autopass License Server16/7/202517/6/2026
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
AnalizadaCrítica (9.8)0.44%—HPE Autopass License Server16/7/202517/6/2026
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
AnalizadaCrítica (9.8)0.62%—HPE Autopass License Server16/7/202517/6/2026
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
AnalizadaAlta (7.5)0.42%—HPE Autopass License Server14/7/202517/6/2026
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
AnalizadaAlta (7.5)0.42%—HPE Autopass License Server14/7/202517/6/2026
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
AnalizadaAlta (8)0.43%—HPE Autopass License Server14/7/202517/6/2026
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
AnalizadaAlta (7.3)1.3%—HPE Autopass License Server14/7/202517/6/2026
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
AplazadaMedia (5.4)0.14%—Siemens License ServerAI8/4/202517/6/2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restrict permissions of the users. This could allow a lowly-privileged attacker to escalate their privileges.
AplazadaMedia (5.4)0.16%—Siemens License ServerAI8/4/202517/6/2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute arbitrary code with administrative privileges by placing a malicious executable…
AplazadaMedia (4.7)0.48%—Numerix License Server Administration SystemAI11/12/202417/6/2026
Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST…
AnalizadaAlta (7.8)0.23%—Ivanti Velocity License Server8/10/202417/6/2026
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
AplazadaCrítica (10)1.1%—PTC Creo Elements Direct License ServerAI27/6/202417/6/2026
PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.
ModificadaAlta (8.8)0.84%—Mimsoftware MIM Concurrent License ServerMimsoftware MIM Local Concurrent License Server9/6/202317/6/2026
An issue found in MIM software Inc MIM License Server and MIMpacs services v.6.9 thru v.7.0 fixed in v.7.0.10 allows a remote unauthenticated attacker to execute arbitrary code via the RMI Registry service.
ModificadaAlta (8.2)1.5%—Kuka Visual Components Network License Server6/11/202017/6/2026
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making processes. Visual Components software requires a special license which can beobtained from a network license server. The network license server binds to all interfaces…
ModificadaAlta (7.5)1.4%—Kuka Visual Components Network License Server6/11/202017/6/2026
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making processes. Visual Components software requires a special license which can beobtained from a network license server. The network license server binds to all interfaces…
ModificadaCrítica (9.8)1.9%—Gemnet License Server20/3/201817/6/2026
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.
ModificadaAlta (7.5)1.8%—Citrix License ServerCitrix License Server VPX7/10/201617/6/2026
The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a…
ModificadaAlta (10)6.8%—IBM Rational License KEY ServerIBM Rational License ServerIBM Telelogic License Server19/1/201216/6/2026
Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and…