Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+11 | 29/7/2025 | 21/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Linux KernelDebian Linux | 22/7/2025 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 20/7/2025 | 4/8/2026 | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the… | |
| Analizada | Alta (7.5) | 4.5% | ⚠ Explotación activa💥 PoC | Eslint-config-prettierEslint-plugin-prettierUn-ts SynckitUn-ts Pkgr/core+3 | 19/7/2025 | 17/6/2026 | eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows. | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 PoC | Crushftp | 18/7/2025 | 17/6/2026 | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025. | |
| Analizada | Crítica (9.2) | 97% | ⚠ Explotación activa💥 Exploit | Laravel Livewire | 17/7/2025 | 17/6/2026 | Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Fortinet Fortiweb | 17/7/2025 | 17/6/2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized… | |
| Analizada | Crítica (10) | 68% | ⚠ Explotación activa | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation… | |
| Analizada | Alta (8.8) | 9.5% | ⚠ Explotación activa💥 PoC | Google ChromeDebian LinuxApple SafariApple Ipados+6 | 15/7/2025 | 1/10/2026 | Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (4.3) | 63% | ⚠ Explotación activa💥 Exploit | Wftpserver Wing FTP Server | 10/7/2025 | 17/6/2026 | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. | |
| Analizada | Crítica (10) | 93% | ⚠ Explotación activa💥 Exploit | Wftpserver Wing FTP Server | 10/7/2025 | 17/6/2026 | In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code… | |
| Analizada | Media (6.5) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 8/7/2025 | 4/8/2026 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 8/7/2025 | 17/6/2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8) | 4.2% | ⚠ Explotación activa💥 PoC | Git-scm GITDebian LinuxApple Xcode | 8/7/2025 | 24/9/2026 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are… | |
| Analizada | Alta (8.1) | 14% | ⚠ Explotación activa💥 PoC | Google Chrome | 30/6/2025 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (7.8) | 55% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+4 | 30/6/2025 | 17/6/2026 | Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | |
| Analizada | Crítica (10) | 98% | ⚠ Explotación activa💥 Exploit | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 25/6/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation… | |
| Analizada | Crítica (9.2) | 11% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 25/6/2025 | 17/6/2026 | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Analizada | Crítica (10) | 2.5% | ⚠ Explotación activa | Quest Kace Systems Management Appliance | 24/6/2025 | 17/6/2026 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.… | |
| Analizada | Media (6.1) | 1.7% | ⚠ Explotación activa | Synacor Zimbra Collaboration Suite | 23/6/2025 | 17/6/2026 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises… | |
| Analizada | Alta (7.8) | 90% | ⚠ Explotación activa💥 PoC | Rarlab Winrar | 21/6/2025 | 17/6/2026 | RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The… | |
| Modificada | Crítica (9.3) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 7/10/2026 | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Analizada | Media (4.2) | 1.2% | ⚠ Explotación activa | Apple IpadosApple Iphone OSApple MacosApple Visionos+1 | 16/6/2025 | 24/9/2026 | This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a… | |
| Analizada | Alta (8.8) | 83% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 10/6/2025 | 17/6/2026 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 87% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 10/6/2025 | 17/6/2026 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. |