Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.19% | — | Magnetosoft Megaping | 26/3/2026 | 17/6/2026 | MegaPing contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload to the Destination Address List field in the Finger function. Attackers can paste a crafted buffer exceeding expected input limits into the vulnerable field and trigger the… | |
| Analizada | Baja (2.3) | 0.30% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Alta (7.1) | 0.14% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM-Based XSS.This issue affects DX NetOps Spectrum: 24.3.9 and earlier. | |
| Analizada | Baja (2.3) | 0.27% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | |
| Analizada | Alta (8.7) | 0.35% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | |
| Analizada | Media (5.3) | 0.17% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier. | |
| Analizada | Baja (2.3) | 0.24% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Baja (2.3) | 0.32% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Alta (7.1) | 0.90% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier. | |
| Analizada | Media (5.3) | 0.16% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Reflected XSS.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Alta (8.8) | 0.33% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Crítica (9.8) | 0.50% | — | Thermofisher ION Torrent Onetouch 2 Firmware | 4/12/2025 | 17/6/2026 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The display server listens on all network interfaces and is accessible over port 6000. The X11 access control list, by default, allows connections from 127.0.0.1 and… | |
| Analizada | Crítica (9.8) | 0.46% | — | Thermofisher ION Torrent Onetouch 2 Firmware | 4/12/2025 | 17/6/2026 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can… | |
| Aplazada | Alta (8.8) | 0.44% | — | Neto CMSAI | 1/10/2025 | 5/7/2026 | A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted HTTP request. | |
| Aplazada | Media (6.5) | 0.34% | — | Neto E-commerce CMSAI | 1/10/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter. | |
| Aplazada | Crítica (9.3) | 1.1% | — | Amlib NetopacsAIMicrosoft IISAI | 21/8/2025 | 16/6/2026 | Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the app parameter, allowing excessive data to overwrite memory structures including the Structured… | |
| Aplazada | Alta (8.4) | 0.49% | — | Netop Remote Control ClientAI | 13/8/2025 | 16/6/2026 | NetOp (now part of Impero Software) Remote Control Client v9.5 is vulnerable to a stack-based buffer overflow when processing .dws configuration files. If a .dws file contains a string longer than 520 bytes, the application fails to perform proper bounds checking, allowing an attacker to execute arbitrary code when… | |
| Modificada | Media (4.8) | 0.91% | — | Raneto Project Raneto | 4/8/2022 | 17/6/2026 | Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Raneto Project Raneto | 4/8/2022 | 17/6/2026 | Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks. | |
| Modificada | Alta (7.5) | 1.5% | — | Raneto Project Raneto | 4/8/2022 | 17/6/2026 | An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter. | |
| Modificada | Crítica (9.8) | 1.8% | — | Siemens Biograph Horizon Pet/ct Systems FirmwareSiemens Magnetom Numaris X FirmwareSiemens Mammomat Revelation FirmwareSiemens Naeotom Alpha Firmware+14 | 1/6/2022 | 17/6/2026 | A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40… | |
| Modificada | Media (6.5) | 0.54% | — | Netop Vision PRO | 27/9/2021 | 17/6/2026 | Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS). | |
| Modificada | Media (5.9) | 0.77% | — | Netop Vision PRO | 25/3/2021 | 17/6/2026 | Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic. | |
| Modificada | Alta (8.8) | 0.36% | — | Netop Vision PRO | 25/3/2021 | 17/6/2026 | Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords. | |
| Modificada | Crítica (9.8) | 1.5% | — | Netop Vision PRO | 25/3/2021 | 17/6/2026 | Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation. |