Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.44%—GE Industrial Gateway ServerPTC KeepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+430/11/202317/6/2026
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
ModificadaCrítica (9.1)0.96%—GE Industrial Gateway ServerPTC KeepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+430/11/202317/6/2026
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
ModificadaCrítica (9.1)3.4%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+429/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation…
ModificadaCrítica (9.8)3.4%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+429/3/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation…
ModificadaAlta (7.5)1.6%—PTC Axeda AgentPTC Axeda Desktop Server16/3/202217/6/2026
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using said function do not handle the exception. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to…
ModificadaCrítica (9.8)1.9%—PTC Axeda AgentPTC Axeda Desktop Server16/3/202217/6/2026
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and…
ModificadaAlta (7.5)1.7%—PTC Axeda AgentPTC Axeda Desktop Server16/3/202217/6/2026
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to shut down a specific…
ModificadaAlta (7.5)2.5%—PTC Axeda AgentPTC Axeda Desktop Server16/3/202217/6/2026
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remote unauthenticated attacker to obtain file system read access via web server..
ModificadaMedia (5.3)0.91%—PTC Axeda AgentPTC Axeda Desktop Server16/3/202217/6/2026
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specific service.
ModificadaCrítica (9.8)4.1%—PTC Axeda AgentPTC Axeda Desktop Server16/3/202217/6/2026
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code…
ModificadaAlta (8.8)1.8%—PTC Axeda AgentPTC Axeda Desktop Server16/3/202217/6/2026
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system.
ModificadaCrítica (9.1)4.9%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+314/1/202117/6/2026
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a…
ModificadaCrítica (9.8)10%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+314/1/202117/6/2026
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a…
ModificadaCrítica (9.1)4.9%—GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+314/1/202117/6/2026
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a…
ModificadaCrítica (9.8)3.8%—Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control6/8/202017/6/2026
Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.
ModificadaAlta (7.8)0.51%—QemuDebian LinuxNovell Open Desktop ServerNovell Open Enterprise Server30/12/201916/6/2026
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus…
ModificadaMedia (5.9)0.73%—Redhat Enterprise VirtualizationRedhat VdsclientRedhat Virtual Desktop Server Manager13/11/201917/6/2026
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
ModificadaMedia (5.5)0.42%—Redhat Virtual Desktop Server ManagerRedhat Enterprise VirtualizationRedhat Storage4/11/201916/6/2026
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
ModificadaMedia (4.4)0.58%—HP Nonstop Server Software15/2/201817/6/2026
A Local Authentication Restriction Bypass vulnerability in HPE NonStop Server version L-Series: T6533L01 through T6533L01^ADN; J-Series and H-series: T6533H02 through T6533H04^ADF and T6533H05 through T6533H05^ADL was found.
ModificadaAlta (7.5)7.5%—HP Nonstop Server Software15/2/201817/6/2026
A Remote Disclosure of Information vulnerability in HPE NonStop Servers using SSH Service version L series: T0801L02 through T0801L02^ABX; J and H series: T0801H01 through T0801H01^ACA was found.
ModificadaMedia (5.5)0.60%—HP Nonstop Server Software15/2/201817/6/2026
A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI was found.
ModificadaAlta (7.1)1.3%—Softwaretoolbox TOP Server28/8/201316/6/2026
The DNP Master Driver in Software Toolbox TOP Server before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input…
ModificadaMedia (6.3)0.52%—HP Nonstop Server SoftwareHP Nonstop Server13/2/201316/6/2026
Multiple unspecified vulnerabilities on HP NonStop Servers H06.x and J06.x allow remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via an OSS Remote Operation over an Expand connection.
ModificadaAlta (9)6.0%—SambaHP Nonstop ServerHP Nonstop Server Software2/10/201116/6/2026
Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors.
ModificadaAlta (7.2)0.44%—HP Nonstop Server2/12/200916/6/2026
Unspecified vulnerability in HP NonStop G06.12.00 through G06.32.00, H06.08.00 through H06.18.01, and J06.04.00 through J06.07.01 allows local users to gain privileges, cause a denial of service, or obtain "access to data" via unknown vectors.