Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.6%⚠ Explotación activa💥 PoCApple SafariApple IpadosApple Iphone OSApple Macos+1129/7/202521/9/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.
AnalizadaAlta (7.8)1.3%⚠ Explotación activa💥 PoCLinux KernelDebian Linux22/7/20258/9/2026
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server20/7/20254/8/2026
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the…
AnalizadaAlta (7.5)4.5%⚠ Explotación activa💥 PoCEslint-config-prettierEslint-plugin-prettierUn-ts SynckitUn-ts Pkgr/core+319/7/202517/6/2026
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 PoCCrushftp18/7/202517/6/2026
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.
AnalizadaCrítica (9.2)97%⚠ Explotación activa💥 ExploitLaravel Livewire17/7/202517/6/2026
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitFortinet Fortiweb17/7/202517/6/2026
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized…
AnalizadaCrítica (10)68%⚠ Explotación activaCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/7/202517/6/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation…
AnalizadaAlta (8.8)9.5%⚠ Explotación activa💥 PoCGoogle ChromeDebian LinuxApple SafariApple Ipados+615/7/20251/10/2026
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
AnalizadaMedia (4.3)63%⚠ Explotación activa💥 ExploitWftpserver Wing FTP Server10/7/202517/6/2026
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.
AnalizadaCrítica (10)93%⚠ Explotación activa💥 ExploitWftpserver Wing FTP Server10/7/202517/6/2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code…
AnalizadaMedia (6.5)99%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server8/7/20254/8/2026
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)100%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server8/7/202517/6/2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8)4.2%⚠ Explotación activa💥 PoCGit-scm GITDebian LinuxApple Xcode8/7/202524/9/2026
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are…
AnalizadaAlta (8.1)14%⚠ Explotación activa💥 PoCGoogle Chrome30/6/202517/6/2026
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (7.8)55%⚠ Explotación activa💥 ExploitSudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+430/6/202517/6/2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
AnalizadaCrítica (10)98%⚠ Explotación activa💥 ExploitCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector25/6/202517/6/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation…
AnalizadaCrítica (9.2)11%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway25/6/202517/6/2026
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AnalizadaCrítica (10)2.5%⚠ Explotación activaQuest Kace Systems Management Appliance24/6/202517/6/2026
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.…
AnalizadaMedia (6.1)1.7%⚠ Explotación activaSynacor Zimbra Collaboration Suite23/6/202517/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises…
AnalizadaAlta (7.8)90%⚠ Explotación activa💥 PoCRarlab Winrar21/6/202517/6/2026
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…
ModificadaCrítica (9.3)100%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/6/20257/10/2026
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AnalizadaMedia (4.2)1.2%⚠ Explotación activaApple IpadosApple Iphone OSApple MacosApple Visionos+116/6/202524/9/2026
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a…
AnalizadaAlta (8.8)83%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1110/6/202517/6/2026
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)87%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1110/6/202517/6/2026
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.