Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 4.1% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 12/3/2025 | 17/6/2026 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript… | |
| Analizada | Media (6.7) | 1.7% | ⚠ Explotación activa | Juniper Junos | 12/3/2025 | 1/10/2026 | An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device. This issue… | |
| Analizada | Crítica (10) | 3.8% | ⚠ Explotación activa💥 PoC | Apple SafariApple MacosApple VisionosApple Watchos+3 | 11/3/2025 | 17/6/2026 | An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web… | |
| Analizada | Media (5.5) | 2.0% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 11/3/2025 | 17/6/2026 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 3.9% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 11/3/2025 | 17/6/2026 | Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (4.6) | 2.0% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 11/3/2025 | 17/6/2026 | Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | |
| Analizada | Alta (7) | 1.4% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows Server 2008Microsoft Windows Server 2012+1 | 11/3/2025 | 17/6/2026 | Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.4) | 59% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 11/3/2025 | 17/6/2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7) | 30% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 11/3/2025 | 24/9/2026 | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7.8) | 2.2% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 11/3/2025 | 24/9/2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.1) | 28% | ⚠ Explotación activa💥 PoC | FreetypeDebian Linux | 11/3/2025 | 17/6/2026 | An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing… | |
| Analizada | Crítica (10) | 61% | ⚠ Explotación activa💥 PoC | AMI Megarac Sp-xNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+6 | 11/3/2025 | 17/6/2026 | AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache TomcatDebian LinuxNetapp Bootstrap OS | 10/3/2025 | 17/6/2026 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1… | |
| Analizada | Crítica (9.3) | 74% | ⚠ Explotación activa | Edimax Ic-7100 Firmware | 5/3/2025 | 17/6/2026 | Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | |
| Analizada | Media (6) | 1.8% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware FusionVmware Telco Cloud Infrastructure+2 | 4/3/2025 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process. | |
| Analizada | Alta (8.2) | 1.0% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 4/3/2025 | 4/8/2026 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. | |
| Analizada | Alta (8.2) | 1.6% | ⚠ Explotación activa | Vmware EsxiVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform+1 | 4/3/2025 | 17/6/2026 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Analizada | Alta (8.6) | 94% | ⚠ Explotación activa💥 Exploit | Nakivo Backup & Replication Director | 4/3/2025 | 24/9/2026 | NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials). | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Xwiki | 20/2/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance,… | |
| Analizada | Crítica (9.8) | 1.6% | ⚠ Explotación activa | Microsoft Power Pages | 19/2/2025 | 17/6/2026 | An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the… | |
| Analizada | Alta (7.1) | 2.0% | ⚠ Explotación activa | Paloaltonetworks Pan-os | 12/2/2025 | 17/6/2026 | An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to… | |
| Analizada | Alta (8.8) | 98% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-os | 12/2/2025 | 24/9/2026 | An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not… | |
| Analizada | Alta (7.8) | 1.6% | ⚠ Explotación activa | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+10 | 11/2/2025 | 17/6/2026 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.1) | 2.3% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+9 | 11/2/2025 | 24/9/2026 | Windows Storage Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.1) | 7.2% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet Fortios | 11/2/2025 | 5/8/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin… |