Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.18% | — | Splashtop Mirroring360 ReceiverSplashtop Mirroring360 SenderSplashtopSplashtop FOR RMM+1 | 25/1/2024 | 17/6/2026 | The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system reboots or when a standard user runs an MSI repair using… | |
| Modificada | Media (4.3) | 0.58% | — | Nokia Fastmile 5G Receiver Firmware | 15/9/2022 | 17/6/2026 | An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key). | |
| Modificada | Alta (7.8) | 6.9% | — | Citrix ReceiverCitrix Xenapp Online | 10/1/2020 | 16/6/2026 | Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver. | |
| Modificada | Media (6.5) | 1.0% | — | Logitech Unifying Receiver FirmwareLogitech K360 Firmware | 29/6/2019 | 17/6/2026 | Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard. | |
| Modificada | Media (6.5) | 0.54% | — | Logitech Unifying Receiver Firmware | 29/6/2019 | 17/6/2026 | Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOTE: this issue exists because of an incomplete fix for CVE-2016-10761. | |
| Modificada | Media (6.5) | 0.67% | — | Logitech Unifying Receiver Firmware | 29/6/2019 | 17/6/2026 | Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed. | |
| Modificada | Media (6.5) | 0.74% | — | Logitech K400r FirmwareLogitech K360 FirmwareLogitech K750 FirmwareLogitech K830 Firmware+1 | 29/6/2019 | 17/6/2026 | Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack. | |
| Analizada | Crítica (9.8) | 8.0% | ⚠ Explotación activa | Citrix ReceiverCitrix Workspace | 22/5/2019 | 12/8/2026 | Citrix Workspace App before 1904 for Windows has Incorrect Access Control. | |
| Modificada | Media (6.8) | 1.8% | — | Citrix Receiver Desktop | 7/11/2016 | 17/6/2026 | Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not reproduce the issue, stating "the researcher was unable to… | |
| Modificada | Media (6.1) | 0.42% | — | Citrix IOS Receiver | 17/6/2016 | 17/6/2026 | Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Mcafee Enterprise Security ManagerMcafee Enterprise Security Manager/log ManagerMcafee Enterprise Security Manager/receiver | 22/9/2015 | 17/6/2026 | McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly… | |
| Modificada | Media (4.3) | 1.1% | — | Trimble Infrastructure Gnss Series Receiver Netr3Trimble Infrastructure Gnss Series Receiver Netr5Trimble Infrastructure Gnss Series Receiver Netr8Trimble Infrastructure Gnss Series Receiver Netr9+1 | 7/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Receiver Web User Interface on Trimble Infrastructure GNSS Series Receivers NetR3, NetR5, NetR8, and NetR9 before 4.70, and NetRS before 1.3-2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 4.9% | — | Citrix ICA Client FOR LinuxCitrix ICA Client FOR SolarisCitrix Online Plug-in FOR MAC FOR Xenapp & XendesktopCitrix Online Plug-in FOR Windows FOR Xenapp & Xendesktop+1 | 11/8/2010 | 16/6/2026 | Citrix Online Plug-in for Windows for XenApp & XenDesktop before 11.2, Citrix Online Plug-in for Mac for XenApp & XenDesktop before 11.0, Citrix ICA Client for Linux before 11.100, Citrix ICA Client for Solaris before 8.63, and Citrix Receiver for Windows Mobile before 11.5 allow remote attackers to execute arbitrary… | |
| Modificada | Media (5.8) | 1.5% | — | Citrix Online Plug-in FOR MACCitrix Online Plug-in FOR WindowsCitrix Receiver FOR Iphone | 13/11/2009 | 16/6/2026 | Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass… |