Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.30% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Alta (7.1) | 0.14% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM-Based XSS.This issue affects DX NetOps Spectrum: 24.3.9 and earlier. | |
| Analizada | Baja (2.3) | 0.27% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | |
| Analizada | Alta (8.7) | 0.35% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier. | |
| Analizada | Media (5.3) | 0.17% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 21.2.1 and earlier. | |
| Analizada | Baja (2.3) | 0.24% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 24.3.13 and earlier. | |
| Analizada | Baja (2.3) | 0.32% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Alta (7.1) | 0.90% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier. | |
| Analizada | Media (5.3) | 0.16% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Reflected XSS.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Analizada | Alta (8.8) | 0.33% | — | Broadcom DX Netops Spectrum | 12/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Path Traversal.This issue affects DX NetOps Spectrum: 24.3.8 and earlier. | |
| Aplazada | Crítica (9.3) | 1.1% | — | Amlib NetopacsAIMicrosoft IISAI | 21/8/2025 | 16/6/2026 | Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the app parameter, allowing excessive data to overwrite memory structures including the Structured… | |
| Aplazada | Alta (8.4) | 0.43% | — | Netop Remote Control ClientAI | 13/8/2025 | 16/6/2026 | NetOp (now part of Impero Software) Remote Control Client v9.5 is vulnerable to a stack-based buffer overflow when processing .dws configuration files. If a .dws file contains a string longer than 520 bytes, the application fails to perform proper bounds checking, allowing an attacker to execute arbitrary code when… | |
| Modificada | Media (6.5) | 0.54% | — | Netop Vision PRO | 27/9/2021 | 17/6/2026 | Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS). | |
| Modificada | Media (5.9) | 0.77% | — | Netop Vision PRO | 25/3/2021 | 17/6/2026 | Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic. | |
| Modificada | Alta (8.8) | 0.36% | — | Netop Vision PRO | 25/3/2021 | 17/6/2026 | Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords. | |
| Modificada | Crítica (9.8) | 1.5% | — | Netop Vision PRO | 25/3/2021 | 17/6/2026 | Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation. | |
| Modificada | Alta (7.8) | 0.22% | — | Netop Vision PRO | 25/3/2021 | 17/6/2026 | Local privilege escalation vulnerability in Windows clients of Netop Vision Pro up to and including 9.7.1 allows a local user to gain administrator privileges whilst using the clients. | |
| Modificada | Media (5.5) | 0.84% | — | Netop Remote Control | 9/1/2017 | 17/6/2026 | Stack-based buffer overflow vulnerability in Netop Remote Control versions 11.53, 12.21 and prior. The affected module in the Guest client is the "Import to Phonebook" option. When a specially designed malicious file containing special characters is loaded, the overflow occurs. 12.51 is the fixed version. The Support… | |
| Modificada | Media (5) | 1.7% | — | Netopia Timbuktu PRO | 14/3/2008 | 16/6/2026 | The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version field or (2) a denial of service (CPU consumption and daemon termination) via an invalid or partial message. | |
| Modificada | Alta (7.5) | 2.9% | — | Netopia Timbuktu PRO | 14/3/2008 | 16/6/2026 | Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user… | |
| Modificada | Alta (10) | 69% | — | Netopia Timbuktu PRO | 14/3/2008 | 16/6/2026 | Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot… | |
| Modificada | Media (5) | 2.2% | — | Danware Data Netop | 9/2/2005 | 16/6/2026 | NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, a "custom" HELO request. | |
| Modificada | Media (5) | 2.0% | — | Netopia Timbuktu PRO MAC | 23/12/2004 | 16/6/2026 | Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407. | |
| Modificada | Media (5) | 3.2% | — | Netopia Timbuktu PRO | 25/3/2002 | 16/6/2026 | Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420). | |
| Modificada | Media (4.6) | 0.33% | — | Crosstec Corporation Netop School | 11/9/2001 | 16/6/2026 | NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version. |