Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.9)94%⚠ Explotación activa💥 ExploitWazuh10/2/202517/6/2026
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using…
AnalizadaMedia (6.1)4.4%⚠ Explotación activaApple IpadosApple Iphone OS10/2/202517/6/2026
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may…
AnalizadaAlta (8.6)31%⚠ Explotación activa💥 PoCTrimble Cityworks6/2/202517/6/2026
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.
AnalizadaAlta (8.8)22%⚠ Explotación activa💥 PoCZyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b FirmwareZyxel Vmg1312-b10e FirmwareZyxel Vmg3312-b10a Firmware+104/2/202517/6/2026
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
AnalizadaAlta (8.8)21%⚠ Explotación activaZyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b FirmwareZyxel Vmg1312-b10e FirmwareZyxel Vmg3312-b10a Firmware+104/2/202517/6/2026
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST…
AnalizadaAlta (8.8)97%⚠ Explotación activa💥 ExploitDigiever Ds-2105 PRO FirmwareDigiever Ds-2105 Pro+ Firmware3/2/202517/6/2026
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AnalizadaAlta (7.5)56%⚠ Explotación activaAdvantive Veracore3/2/202517/6/2026
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
AnalizadaAlta (8.8)32%⚠ Explotación activaAdvantive Veracore3/2/202517/6/2026
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
AnalizadaCrítica (10)18%⚠ Explotación activa💥 ExploitApple IpadosApple Iphone OSApple MacosApple Tvos+227/1/202517/6/2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a…
AnalizadaAlta (7)67%⚠ Explotación activa💥 PoCNetapp Active IQ Unified Manager7-zip25/1/202517/6/2026
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…
AnalizadaCrítica (9.8)23%⚠ Explotación activaSonicwall Sma8200vSonicwall Sma6200 FirmwareSonicwall Sma6210 FirmwareSonicwall Sma7200 Firmware+423/1/202524/9/2026
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.
AnalizadaAlta (8.1)22%⚠ Explotación activaCraftcms Craft CMS18/1/202517/6/2026
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security…
AnalizadaAlta (7.2)65%⚠ Explotación activa💥 ExploitSimple-help Simplehelp15/1/202517/6/2026
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
AnalizadaAlta (7.5)97%⚠ Explotación activa💥 ExploitSimple-help Simplehelp15/1/20254/8/2026
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed…
AnalizadaCrítica (9.9)67%⚠ Explotación activa💥 ExploitSimple-help Simplehelp15/1/202517/6/2026
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
AnalizadaAlta (7.8)1.6%⚠ Explotación activaMicrosoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+314/1/202517/6/2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)10.0%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+314/1/202517/6/2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
AnalizadaAlta (7.5)90%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.5)91%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager14/1/202517/6/2026
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.8)1.4%⚠ Explotación activaMicrosoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+314/1/202524/9/2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)94%⚠ Explotación activa💥 ExploitFortinet FortiproxyFortinet Fortios14/1/20255/8/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 ExploitSonicwall Sonicos9/1/20254/8/2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure8/1/20251/10/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitAviatrix Controller8/1/202517/6/2026
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for…
Orbitaley — Vulnerabilidades