Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.9% | ⚠ Explotación activa | Srimax Output Messenger | 5/5/2025 | 17/6/2026 | Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access. | |
| Analizada | Alta (7.2) | 3.5% | ⚠ Explotación activa | Connectwise Screenconnect | 25/4/2025 | 17/6/2026 | ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to note that to obtain these machine keys, privileged system level… | |
| Modificada | Alta (8.7) | 2.3% | ⚠ Explotación activa | Commvault | 25/4/2025 | 7/10/2026 | Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Craftcms Craft CMS | 25/4/2025 | 24/9/2026 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | SAP Netweaver | 24/4/2025 | 4/8/2026 | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted… | |
| Analizada | Alta (8.6) | 0.69% | ⚠ Explotación activa | Broadcom Fabric Operating System | 24/4/2025 | 17/6/2026 | Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6. | |
| Analizada | Crítica (9.3) | 98% | ⚠ Explotación activa💥 Exploit | Commvault | 22/4/2025 | 17/6/2026 | The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center… | |
| Analizada | Crítica (9.8) | 3.3% | ⚠ Explotación activa | Qualitia Active! Mail | 18/4/2025 | 24/9/2026 | Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition. | |
| Analizada | Crítica (10) | 99% | ⚠ Explotación activa💥 Exploit | Erlang/otpCisco Confd BasicCisco Network Services OrchestratorCisco Cloud Native Broadband Network Gateway+19 | 16/4/2025 | 17/6/2026 | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain… | |
| Analizada | Crítica (9.8) | 14% | ⚠ Explotación activa | Apple MacosApple TvosApple VisionosApple Ipados+1 | 16/4/2025 | 17/6/2026 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been… | |
| Analizada | Crítica (9.8) | 19% | ⚠ Explotación activa💥 PoC | Apple MacosApple TvosApple VisionosApple Ipados+2 | 16/4/2025 | 17/6/2026 | A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this… | |
| Analizada | Crítica (9.8) | 88% | ⚠ Explotación activa💥 Exploit | Yiiframework YII | 10/4/2025 | 17/6/2026 | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. | |
| Analizada | Alta (7.8) | 14% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 8/4/2025 | 17/6/2026 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Langflow | 7/4/2025 | 14/7/2026 | Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Crushftp | 3/4/2025 | 17/6/2026 | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible with S3)… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | Gladinet Centrestack | 3/4/2025 | 17/6/2026 | Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway | 3/4/2025 | 4/8/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Alta (7.5) | 65% | ⚠ Explotación activa💥 Exploit | Vitejs Vite | 31/3/2025 | 17/6/2026 | Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and… | |
| Analizada | Alta (8.3) | 9.2% | ⚠ Explotación activa💥 Exploit | Google Chrome | 26/3/2025 | 17/6/2026 | Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High) | |
| Analizada | Alta (7.2) | 88% | ⚠ Explotación activa💥 Exploit | Dlink Dir-823x Firmware | 25/3/2025 | 17/6/2026 | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution. | |
| Analizada | Alta (7.2) | 4.1% | ⚠ Explotación activa | Kentico Xperience | 24/3/2025 | 17/6/2026 | An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Kentico Xperience | 24/3/2025 | 17/6/2026 | An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178. | |
| Analizada | Crítica (9.8) | 73% | ⚠ Explotación activa💥 Exploit | Kentico Xperience | 24/3/2025 | 17/6/2026 | An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172. | |
| Analizada | Alta (8.6) | 2.4% | ⚠ Explotación activa | Reviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+2 | 19/3/2025 | 17/6/2026 | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be… | |
| Analizada | Alta (8.6) | 72% | ⚠ Explotación activa💥 PoC | Tj-actions Changed-files | 15/3/2025 | 24/9/2026 | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.) |