Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)5.4%⚠ Explotación activa💥 PoCGoogle ChromeSiemens Cadra24/9/202514/7/2026
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (7.7)39%⚠ Explotación activa💥 PoCCisco IOS XE Sd-wanCisco IOS XECisco IOS24/9/202525/9/2026
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco…
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitSolarwinds WEB Help Desk23/9/202517/6/2026
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of…
AnalizadaMedia (6.1)1.9%⚠ Explotación activaLibraesva Email Security Gateway19/9/202517/6/2026
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has…
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitControl-webpanel Webpanel19/9/202517/6/2026
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitFortra Goanywhere Managed File Transfer18/9/20254/8/2026
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
AnalizadaCrítica (9.3)91%⚠ Explotación activa💥 PoCWatchguard Fireware17/9/202510/8/2026
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was…
AnalizadaCrítica (9.8)2.1%⚠ Explotación activaSamsung Android12/9/202517/6/2026
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
ModificadaCrítica (9.8)33%⚠ Explotación activa💥 PoCSamsung Android12/9/20257/10/2026
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
AnalizadaCrítica (9.1)95%⚠ Explotación activa💥 ExploitAdobe CommerceAdobe Commerce B2BAdobe Magento9/9/202517/6/2026
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue…
AnalizadaCrítica (9.8)2.9%⚠ Explotación activa💥 PoCLinux KernelDebian LinuxSiemens Simatic CN 4100 Firmware5/9/20257/10/2026
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we…
AnalizadaAlta (8.8)0.54%⚠ Explotación activa💥 PoCGoogle Android4/9/202517/6/2026
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaCrítica (9)51%⚠ Explotación activa💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
AnalizadaAlta (8.6)36%⚠ Explotación activaTp-link Tl-wr841n FirmwareTp-link Tl-wr841nd FirmwareTp-link Archer C7 Firmware29/8/202517/6/2026
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's…
ModificadaMedia (5.4)4.7%⚠ Explotación activa💥 PoCWhatsappWhatsapp Business29/8/20257/10/2026
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this…
AnalizadaCrítica (10)86%⚠ Explotación activa💥 ExploitSangoma Freepbx28/8/202525/9/2026
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in…
AnalizadaCrítica (9.2)20%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway26/8/202517/6/2026
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB…
AnalizadaCrítica (10)32%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple Macos21/8/202517/6/2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in…
AnalizadaCrítica (9.4)3.4%⚠ Explotación activaN-able N-central14/8/202517/6/2026
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
AnalizadaCrítica (9.4)1.9%⚠ Explotación activa💥 PoCN-able N-central14/8/202524/9/2026
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
AnalizadaAlta (8.4)94%⚠ Explotación activa💥 PoCRarlab WinrarDtsearch8/8/202511/8/2026
—
AnalizadaCrítica (10)88%⚠ Explotación activa💥 PoCAdobe Experience Manager Forms5/8/202517/6/2026
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is…
AnalizadaCrítica (9.8)24%⚠ Explotación activaTrendmicro Apex ONE5/8/202517/6/2026
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
AnalizadaCrítica (9.1)74%⚠ Explotación activa💥 Exploit3DS Delmia Apriso4/8/202517/6/2026
A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.
AnalizadaAlta (8)79%⚠ Explotación activa💥 Exploit3DS Delmia Apriso4/8/202517/6/2026
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.
Orbitaley — Vulnerabilidades