Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 329 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.96% | — | Cybozu Remote Service Manager | 3/8/2023 | 17/6/2026 | Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition. | |
| Modificada | Media (6.1) | 0.75% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.1) | 0.82% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors. | |
| Modificada | Media (5.4) | 0.72% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen. | |
| Modificada | Media (5.3) | 0.99% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product. | |
| Modificada | Media (6.5) | 1.1% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox. | |
| Modificada | Media (5.4) | 0.60% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.61% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox. | |
| Modificada | Media (6.5) | 1.5% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.56% | — | Cybozu Remote Service Manager | 13/10/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors. | |
| Modificada | Media (6.5) | 0.60% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate. | |
| Modificada | Alta (8.8) | 1.9% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors. | |
| Modificada | Alta (8.1) | 1.7% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.3% | — | Cybozu Remote Service Manager | 9/1/2019 | 17/6/2026 | Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors. | |
| Modificada | Media (4.2) | 0.45% | — | Cybozu Remote Service Manager | 28/4/2017 | 17/6/2026 | Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network. | |
| Modificada | Alta (7.8) | 1.8% | — | Cybozu Remote Service Manager | 1/2/2015 | 17/6/2026 | Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1983. | |
| Modificada | Media (6.8) | 1.7% | — | Cybozu Remote Service Manager | 19/4/2014 | 17/6/2026 | Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.3% | — | Cybozu Remote Service Manager | 19/4/2014 | 17/6/2026 | Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (CPU consumption) via unknown vectors. |