Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.59% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 4/10/2026 | 5/10/2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28. | |
| Analizada | Crítica (9.8) | 2.2% | ⚠ Explotación activa💥 PoC | Fortinet Fortimail | 1/10/2026 | 2/10/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system… | |
| Analizada | Crítica (9.4) | 0.63% | ⚠ Explotación activa | Zammad | 30/9/2026 | 3/10/2026 | All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | |
| Analizada | Crítica (9.4) | 1.4% | ⚠ Explotación activa | Zammad | 30/9/2026 | 3/10/2026 | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions. | |
| Analizada | Crítica (9.8) | 1.8% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan Manager | 30/9/2026 | 2/10/2026 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request… | |
| Analizada | Alta (8.8) | 1.2% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple Macos | 28/9/2026 | 1/10/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an… | |
| Analizada | Crítica (9.5) | 1.3% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 28/9/2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service | |
| Analizada | Crítica (9.5) | 1.1% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute… | |
| Analizada | Alta (8.1) | 46% | ⚠ Explotación activa💥 Exploit | Wordpress | 22/9/2026 | 28/9/2026 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE. | |
| Analizada | Crítica (9.3) | 2.2% | ⚠ Explotación activa💥 PoC | F5 Big-ip Access Policy Manager | 22/9/2026 | 23/9/2026 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource… | |
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa💥 PoC | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | |
| Analizada | Crítica (9.5) | 1.1% | ⚠ Explotación activa | Arista Velocloud Orchestrator | 22/9/2026 | 23/9/2026 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.… | |
| Analizada | Alta (7.8) | 0.23% | ⚠ Explotación activa | Acronis Backup | 17/9/2026 | 18/9/2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238. | |
| Analizada | Crítica (10) | 14% | ⚠ Explotación activa💥 PoC | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 25/9/2026 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API… | |
| Analizada | Alta (8.8) | 0.59% | ⚠ Explotación activa | Google Android | 15/9/2026 | 17/9/2026 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Crítica (9.8) | 28% | ⚠ Explotación activa💥 PoC | Cisco Asyncos | 14/9/2026 | 15/9/2026 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An… | |
| Analizada | Crítica (10) | 93% | ⚠ Explotación activa💥 Exploit | Gitlab | 12/9/2026 | 24/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path… | |
| Analizada | Crítica (9.8) | 7.5% | ⚠ Explotación activa | Checkpoint Gaia EmbeddedCheckpoint Gaia OS | 9/9/2026 | 23/9/2026 | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. | |
| Analizada | Alta (8.8) | 3.1% | ⚠ Explotación activa💥 PoC | Google Chrome | 8/9/2026 | 21/9/2026 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.9) | 0.92% | ⚠ Explotación activa | Connectwise Screenconnect | 8/9/2026 | 12/9/2026 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. | |
| Analizada | Alta (7.8) | 0.39% | ⚠ Explotación activa | Microsoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1+1 | 8/9/2026 | 9/9/2026 | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 3.6% | ⚠ Explotación activa | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+4 | 8/9/2026 | 24/9/2026 | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (10) | 3.9% | ⚠ Explotación activa💥 PoC | Adobe CommerceAdobe Commerce B2BAdobe Magento | 7/9/2026 | 9/9/2026 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user… | |
| Analizada | Crítica (10) | 13% | ⚠ Explotación activa💥 Exploit | N-able N-central | 6/9/2026 | 9/9/2026 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | |
| Analizada | Crítica (9.2) | 6.4% | ⚠ Explotación activa💥 Exploit | Mikrotik Routeros | 5/9/2026 | 11/9/2026 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue… |