Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.44% | — | GE Industrial Gateway ServerPTC KeepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 30/11/2023 | 17/6/2026 | KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect. | |
| Modificada | Crítica (9.1) | 0.96% | — | GE Industrial Gateway ServerPTC KeepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 30/11/2023 | 17/6/2026 | KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information. | |
| Modificada | Crítica (9.1) | 3.4% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation… | |
| Modificada | Crítica (9.8) | 3.4% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation… | |
| Modificada | Alta (7.5) | 1.6% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using said function do not handle the exception. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to… | |
| Modificada | Crítica (9.8) | 1.9% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to read and… | |
| Modificada | Alta (7.5) | 1.7% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a certain command to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to shut down a specific… | |
| Modificada | Alta (7.5) | 2.5% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remote unauthenticated attacker to obtain file system read access via web server.. | |
| Modificada | Media (5.3) | 0.91% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specific service. | |
| Modificada | Crítica (9.8) | 4.1% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full file-system access and remote code… | |
| Modificada | Alta (8.8) | 1.8% | — | PTC Axeda AgentPTC Axeda Desktop Server | 16/3/2022 | 17/6/2026 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating system. | |
| Modificada | Crítica (9.1) | 4.9% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+3 | 14/1/2021 | 17/6/2026 | KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a… | |
| Modificada | Crítica (9.8) | 10% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+3 | 14/1/2021 | 17/6/2026 | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a… | |
| Modificada | Crítica (9.1) | 4.9% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+3 | 14/1/2021 | 17/6/2026 | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a… | |
| Modificada | Crítica (9.8) | 3.8% | — | Ivanti Desktop&server ManagementIvanti Service Manager Heat Remote Control | 6/8/2020 | 17/6/2026 | Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet. | |
| Modificada | Alta (7.8) | 0.51% | — | QemuDebian LinuxNovell Open Desktop ServerNovell Open Enterprise Server | 30/12/2019 | 16/6/2026 | A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus… | |
| Modificada | Media (5.9) | 0.73% | — | Redhat Enterprise VirtualizationRedhat VdsclientRedhat Virtual Desktop Server Manager | 13/11/2019 | 17/6/2026 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack | |
| Modificada | Media (5.5) | 0.42% | — | Redhat Virtual Desktop Server ManagerRedhat Enterprise VirtualizationRedhat Storage | 4/11/2019 | 16/6/2026 | Insecure temporary file vulnerability in RedHat vsdm 4.9.6. | |
| Modificada | Media (4.4) | 0.58% | — | HP Nonstop Server Software | 15/2/2018 | 17/6/2026 | A Local Authentication Restriction Bypass vulnerability in HPE NonStop Server version L-Series: T6533L01 through T6533L01^ADN; J-Series and H-series: T6533H02 through T6533H04^ADF and T6533H05 through T6533H05^ADL was found. | |
| Modificada | Alta (7.5) | 7.5% | — | HP Nonstop Server Software | 15/2/2018 | 17/6/2026 | A Remote Disclosure of Information vulnerability in HPE NonStop Servers using SSH Service version L series: T0801L02 through T0801L02^ABX; J and H series: T0801H01 through T0801H01^ACA was found. | |
| Modificada | Media (5.5) | 0.60% | — | HP Nonstop Server Software | 15/2/2018 | 17/6/2026 | A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI was found. | |
| Modificada | Alta (7.1) | 1.3% | — | Softwaretoolbox TOP Server | 28/8/2013 | 16/6/2026 | The DNP Master Driver in Software Toolbox TOP Server before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input… | |
| Modificada | Media (6.3) | 0.52% | — | HP Nonstop Server SoftwareHP Nonstop Server | 13/2/2013 | 16/6/2026 | Multiple unspecified vulnerabilities on HP NonStop Servers H06.x and J06.x allow remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via an OSS Remote Operation over an Expand connection. | |
| Modificada | Alta (9) | 6.0% | — | SambaHP Nonstop ServerHP Nonstop Server Software | 2/10/2011 | 16/6/2026 | Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.2) | 0.44% | — | HP Nonstop Server | 2/12/2009 | 16/6/2026 | Unspecified vulnerability in HP NonStop G06.12.00 through G06.32.00, H06.08.00 through H06.18.01, and J06.04.00 through J06.07.01 allows local users to gain privileges, cause a denial of service, or obtain "access to data" via unknown vectors. |