Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.6) | 4.9% | ⚠ Explotación activa💥 PoC | Igel OSMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+12 | 5/6/2025 | 17/6/2026 | In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. | |
| Analizada | Alta (8.6) | 0.84% | ⚠ Explotación activa💥 PoC | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+71 | 3/6/2025 | 17/6/2026 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | |
| Analizada | Alta (7.5) | 1.0% | ⚠ Explotación activa | Qualcomm Ar8031 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 7800 Firmware+40 | 3/6/2025 | 17/6/2026 | Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | |
| Analizada | Alta (8.6) | 0.46% | ⚠ Explotación activa | Qualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+72 | 3/6/2025 | 17/6/2026 | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | |
| Analizada | Alta (8.8) | 7.8% | ⚠ Explotación activa💥 PoC | Google ChromeMicrosoft Edge Chromium | 3/6/2025 | 17/6/2026 | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9) | 97% | ⚠ Explotación activa💥 Exploit | 3DS Delmia Apriso | 2/6/2025 | 17/6/2026 | A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution. | |
| Analizada | Alta (8.8) | 99% | ⚠ Explotación activa💥 Exploit | Roundcube WebmailDebian Linux | 2/6/2025 | 17/6/2026 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. | |
| Analizada | Media (4) | 0.55% | ⚠ Explotación activa | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025. | |
| Analizada | Media (5.3) | 11% | ⚠ Explotación activa | Smarsh Telemessage | 28/5/2025 | 17/6/2026 | The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025. | |
| Analizada | Crítica (9.2) | 82% | ⚠ Explotación activa💥 Exploit | Versa-networks Concerto | 21/5/2025 | 17/6/2026 | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto… | |
| Analizada | Alta (8.7) | 94% | ⚠ Explotación activa💥 Exploit | Smartbedded Meteobridge VMSmartbedded Meteobridge Firmware | 21/5/2025 | 17/6/2026 | The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers… | |
| Analizada | Alta (7.8) | 2.2% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 13/5/2025 | 17/6/2026 | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 2.3% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 13/5/2025 | 17/6/2026 | Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 1.4% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 13/5/2025 | 17/6/2026 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 1.9% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2+6 | 13/5/2025 | 17/6/2026 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 27% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 13/5/2025 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 87% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 13/5/2025 | 17/6/2026 | Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 13/5/2025 | 17/6/2026 | An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API. | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa💥 PoC | Fortinet FortimailFortinet FortindrFortinet FortirecorderFortinet Fortivoice+1 | 13/5/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0,… | |
| Analizada | Crítica (9.8) | 24% | ⚠ Explotación activa💥 Exploit | Samsung Magicinfo 9 Server | 13/5/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority. | |
| Analizada | Crítica (9.1) | 14% | ⚠ Explotación activa | SAP Netweaver | 13/5/2025 | 11/8/2026 | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system. | |
| Analizada | Media (4.9) | 0.45% | ⚠ Explotación activa | Telemessage Text Message Archiver | 8/5/2025 | 17/6/2026 | The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild… | |
| Analizada | Media (6.9) | 1.3% | ⚠ Explotación activa | Craftcms Craft CMS | 7/5/2025 | 17/6/2026 | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at… | |
| Analizada | Crítica (9.8) | 65% | ⚠ Explotación activa💥 Exploit | Sysaid | 7/5/2025 | 17/6/2026 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. | |
| Analizada | Alta (7.5) | 43% | ⚠ Explotación activa💥 Exploit | Sysaid | 7/5/2025 | 17/6/2026 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives. |