Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.62% | — | 1000projects Campaign Management System Platform FOR Women | 17/1/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Code/loginnew.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.9) | 0.62% | — | 1000projects Campaign Management System Platform FOR Women | 17/1/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Code/sc_login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely.… | |
| Modificada | Alta (7.1) | 0.22% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service. | |
| Modificada | Alta (7.8) | 0.24% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine. | |
| Modificada | Alta (7.8) | 0.22% | — | Aveva Batch ManagementAveva Enterprise Data ManagementAveva Manufacturing Execution SystemAveva Mobile Operator+3 | 27/7/2022 | 17/6/2026 | AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path. | |
| Modificada | Media (5.5) | 0.17% | — | Aveva System Platform | 11/4/2022 | 17/6/2026 | AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user. | |
| Modificada | Alta (7.5) | 1.1% | — | Aveva System Platform | 4/4/2022 | 17/6/2026 | An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition. | |
| Modificada | Crítica (9.8) | 1.2% | — | Aveva System Platform | 4/4/2022 | 17/6/2026 | AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity. | |
| Modificada | Alta (7.2) | 0.50% | — | Aveva System Platform | 4/4/2022 | 17/6/2026 | AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid. | |
| Modificada | Alta (7.2) | 1.2% | — | Aveva System Platform | 4/4/2022 | 17/6/2026 | AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname… | |
| Modificada | Alta (7.2) | 0.64% | — | Aveva System Platform | 4/4/2022 | 17/6/2026 | AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data. | |
| Modificada | Alta (7.5) | 1.3% | — | Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform | 1/4/2022 | 17/6/2026 | A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get… | |
| Modificada | Alta (7.5) | 0.89% | — | Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform | 1/4/2022 | 17/6/2026 | A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable… | |
| Modificada | Crítica (9.8) | 1.2% | — | Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform | 1/4/2022 | 17/6/2026 | An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login. | |
| Modificada | Alta (7.5) | 1.1% | — | Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform | 1/4/2022 | 17/6/2026 | An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file. | |
| Modificada | Alta (7.5) | 0.41% | — | Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform | 1/4/2022 | 17/6/2026 | An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06. | |
| Modificada | Alta (7.5) | 1.1% | — | Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform | 1/4/2022 | 17/6/2026 | An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated. | |
| Modificada | Crítica (9.8) | 1.2% | — | Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform | 1/4/2022 | 17/6/2026 | An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process. | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+23 | 15/11/2019 | 17/6/2026 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. | |
| Modificada | Alta (8.8) | 1.3% | — | Aveva Wonderware System Platform | 11/4/2019 | 17/6/2026 | AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account. | |
| Modificada | Crítica (9.8) | 3.3% | — | Avaya Aura System Platform | 17/10/2018 | 17/6/2026 | A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2. | |
| Modificada | Alta (8.4) | 0.40% | — | Cisco Unified Computing System Platform Emulator | 16/4/2016 | 17/6/2026 | Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCux68837. | |
| Modificada | Alta (7.8) | 0.37% | — | Cisco Unified Computing System Platform Emulator | 16/4/2016 | 17/6/2026 | Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832. | |
| Modificada | Media (6.9) | 0.46% | — | Schneider-electric Wonderware System Platform 2014 | 4/8/2015 | 17/6/2026 | Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (8.1) | 17% | — | Linux KernelCanonical Ubuntu LinuxVmware ESXAvaya Aura Communication Manager+6 | 30/9/2010 | 16/6/2026 | The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked… |