Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.62%—1000projects Campaign Management System Platform FOR Women17/1/202517/6/2026
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Code/loginnew.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (6.9)0.62%—1000projects Campaign Management System Platform FOR Women17/1/202517/6/2026
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Code/sc_login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely.…
ModificadaAlta (7.1)0.22%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
ModificadaAlta (7.8)0.24%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
ModificadaAlta (7.8)0.22%—Aveva Batch ManagementAveva Enterprise Data ManagementAveva Manufacturing Execution SystemAveva Mobile Operator+327/7/202217/6/2026
AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.
ModificadaMedia (5.5)0.17%—Aveva System Platform11/4/202217/6/2026
AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.
ModificadaAlta (7.5)1.1%—Aveva System Platform4/4/202217/6/2026
An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.
ModificadaCrítica (9.8)1.2%—Aveva System Platform4/4/202217/6/2026
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.
ModificadaAlta (7.2)0.50%—Aveva System Platform4/4/202217/6/2026
AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.
ModificadaAlta (7.2)1.2%—Aveva System Platform4/4/202217/6/2026
AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname…
ModificadaAlta (7.2)0.64%—Aveva System Platform4/4/202217/6/2026
AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.
ModificadaAlta (7.5)1.3%—Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform1/4/202217/6/2026
A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the locations the function looks for and get…
ModificadaAlta (7.5)0.89%—Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform1/4/202217/6/2026
A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable…
ModificadaCrítica (9.8)1.2%—Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform1/4/202217/6/2026
An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.
ModificadaAlta (7.5)1.1%—Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform1/4/202217/6/2026
An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.
ModificadaAlta (7.5)0.41%—Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform1/4/202217/6/2026
An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.
ModificadaAlta (7.5)1.1%—Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform1/4/202217/6/2026
An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.
ModificadaCrítica (9.8)1.2%—Auvesy-mdt AutosaveAuvesy-mdt Autosave FOR System Platform1/4/202217/6/2026
An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process.
ModificadaAlta (7.5)2.3%—Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+2315/11/201917/6/2026
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
ModificadaAlta (8.8)1.3%—Aveva Wonderware System Platform11/4/201917/6/2026
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.
ModificadaCrítica (9.8)3.3%—Avaya Aura System Platform17/10/201817/6/2026
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
ModificadaAlta (8.4)0.40%—Cisco Unified Computing System Platform Emulator16/4/201617/6/2026
Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCux68837.
ModificadaAlta (7.8)0.37%—Cisco Unified Computing System Platform Emulator16/4/201617/6/2026
Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.
ModificadaMedia (6.9)0.46%—Schneider-electric Wonderware System Platform 20144/8/201517/6/2026
Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (8.1)17%—Linux KernelCanonical Ubuntu LinuxVmware ESXAvaya Aura Communication Manager+630/9/201016/6/2026
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked…