Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.6)4.9%⚠ Explotación activa💥 PoCIgel OSMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+125/6/202517/6/2026
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.
AnalizadaAlta (8.6)0.84%⚠ Explotación activa💥 PoCQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+713/6/202517/6/2026
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
AnalizadaAlta (7.5)1.0%⚠ Explotación activaQualcomm Ar8031 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 7800 Firmware+403/6/202517/6/2026
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
AnalizadaAlta (8.6)0.46%⚠ Explotación activaQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+723/6/202517/6/2026
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
AnalizadaAlta (8.8)7.8%⚠ Explotación activa💥 PoCGoogle ChromeMicrosoft Edge Chromium3/6/202517/6/2026
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaCrítica (9)97%⚠ Explotación activa💥 Exploit3DS Delmia Apriso2/6/202517/6/2026
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
AnalizadaAlta (8.8)99%⚠ Explotación activa💥 ExploitRoundcube WebmailDebian Linux2/6/202517/6/2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
AnalizadaMedia (4)0.55%⚠ Explotación activaSmarsh Telemessage28/5/202517/6/2026
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.
AnalizadaMedia (5.3)11%⚠ Explotación activaSmarsh Telemessage28/5/202517/6/2026
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.
AnalizadaCrítica (9.2)82%⚠ Explotación activa💥 ExploitVersa-networks Concerto21/5/202517/6/2026
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto…
AnalizadaAlta (8.7)94%⚠ Explotación activa💥 ExploitSmartbedded Meteobridge VMSmartbedded Meteobridge Firmware21/5/202517/6/2026
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers…
AnalizadaAlta (7.8)2.2%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1113/5/202517/6/2026
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)2.3%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1113/5/202517/6/2026
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)1.4%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1113/5/202517/6/2026
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)1.9%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2+613/5/202517/6/2026
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)27%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1113/5/202517/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)87%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Mobile13/5/202517/6/2026
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Mobile13/5/202517/6/2026
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
AnalizadaCrítica (9.8)30%⚠ Explotación activa💥 PoCFortinet FortimailFortinet FortindrFortinet FortirecorderFortinet Fortivoice+113/5/202517/6/2026
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0,…
AnalizadaCrítica (9.8)24%⚠ Explotación activa💥 ExploitSamsung Magicinfo 9 Server13/5/202517/6/2026
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
AnalizadaCrítica (9.1)14%⚠ Explotación activaSAP Netweaver13/5/202511/8/2026
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
AnalizadaMedia (4.9)0.45%⚠ Explotación activaTelemessage Text Message Archiver8/5/202517/6/2026
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild…
AnalizadaMedia (6.9)1.3%⚠ Explotación activaCraftcms Craft CMS7/5/202517/6/2026
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at…
AnalizadaCrítica (9.8)65%⚠ Explotación activa💥 ExploitSysaid7/5/202517/6/2026
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
AnalizadaAlta (7.5)43%⚠ Explotación activa💥 ExploitSysaid7/5/202517/6/2026
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.