Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.18%—Splashtop Mirroring360 ReceiverSplashtop Mirroring360 SenderSplashtopSplashtop FOR RMM+125/1/202417/6/2026
The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system reboots or when a standard user runs an MSI repair using…
ModificadaMedia (4.3)0.58%—Nokia Fastmile 5G Receiver Firmware15/9/202217/6/2026
An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).
ModificadaAlta (7.8)6.9%—Citrix ReceiverCitrix Xenapp Online10/1/202016/6/2026
Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.
ModificadaMedia (6.5)1.0%—Logitech Unifying Receiver FirmwareLogitech K360 Firmware29/6/201917/6/2026
Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard.
ModificadaMedia (6.5)0.54%—Logitech Unifying Receiver Firmware29/6/201917/6/2026
Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOTE: this issue exists because of an incomplete fix for CVE-2016-10761.
ModificadaMedia (6.5)0.67%—Logitech Unifying Receiver Firmware29/6/201917/6/2026
Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.
ModificadaMedia (6.5)0.74%—Logitech K400r FirmwareLogitech K360 FirmwareLogitech K750 FirmwareLogitech K830 Firmware+129/6/201917/6/2026
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
AnalizadaCrítica (9.8)8.0%⚠ Explotación activaCitrix ReceiverCitrix Workspace22/5/201912/8/2026
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
ModificadaMedia (6.8)1.8%—Citrix Receiver Desktop7/11/201617/6/2026
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not reproduce the issue, stating "the researcher was unable to…
ModificadaMedia (6.1)0.42%—Citrix IOS Receiver17/6/201617/6/2026
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.
ModificadaMedia (6.5)1.1%—Mcafee Enterprise Security ManagerMcafee Enterprise Security Manager/log ManagerMcafee Enterprise Security Manager/receiver22/9/201517/6/2026
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly…
ModificadaMedia (4.3)1.1%—Trimble Infrastructure Gnss Series Receiver Netr3Trimble Infrastructure Gnss Series Receiver Netr5Trimble Infrastructure Gnss Series Receiver Netr8Trimble Infrastructure Gnss Series Receiver Netr9+17/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Receiver Web User Interface on Trimble Infrastructure GNSS Series Receivers NetR3, NetR5, NetR8, and NetR9 before 4.70, and NetRS before 1.3-2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)4.9%—Citrix ICA Client FOR LinuxCitrix ICA Client FOR SolarisCitrix Online Plug-in FOR MAC FOR Xenapp & XendesktopCitrix Online Plug-in FOR Windows FOR Xenapp & Xendesktop+111/8/201016/6/2026
Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary…
ModificadaMedia (5.8)1.5%—Citrix Online Plug-in FOR MACCitrix Online Plug-in FOR WindowsCitrix Receiver FOR Iphone13/11/200916/6/2026
Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass…