Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 94% | ⚠ Explotación activa💥 Exploit | Wazuh | 10/2/2025 | 17/6/2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using… | |
| Analizada | Media (6.1) | 4.4% | ⚠ Explotación activa | Apple IpadosApple Iphone OS | 10/2/2025 | 17/6/2026 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may… | |
| Analizada | Alta (8.6) | 31% | ⚠ Explotación activa💥 PoC | Trimble Cityworks | 6/2/2025 | 17/6/2026 | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server. | |
| Analizada | Alta (8.8) | 22% | ⚠ Explotación activa💥 PoC | Zyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b FirmwareZyxel Vmg1312-b10e FirmwareZyxel Vmg3312-b10a Firmware+10 | 4/2/2025 | 17/6/2026 | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet. | |
| Analizada | Alta (8.8) | 21% | ⚠ Explotación activa | Zyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b FirmwareZyxel Vmg1312-b10e FirmwareZyxel Vmg3312-b10a Firmware+10 | 4/2/2025 | 17/6/2026 | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST… | |
| Analizada | Alta (8.8) | 97% | ⚠ Explotación activa💥 Exploit | Digiever Ds-2105 PRO FirmwareDigiever Ds-2105 Pro+ Firmware | 3/2/2025 | 17/6/2026 | Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Analizada | Alta (7.5) | 56% | ⚠ Explotación activa | Advantive Veracore | 3/2/2025 | 17/6/2026 | A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter. | |
| Analizada | Alta (8.8) | 32% | ⚠ Explotación activa | Advantive Veracore | 3/2/2025 | 17/6/2026 | Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this. | |
| Analizada | Crítica (10) | 18% | ⚠ Explotación activa💥 Exploit | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 27/1/2025 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a… | |
| Analizada | Alta (7) | 67% | ⚠ Explotación activa💥 PoC | Netapp Active IQ Unified Manager7-zip | 25/1/2025 | 17/6/2026 | 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific… | |
| Analizada | Crítica (9.8) | 23% | ⚠ Explotación activa | Sonicwall Sma8200vSonicwall Sma6200 FirmwareSonicwall Sma6210 FirmwareSonicwall Sma7200 Firmware+4 | 23/1/2025 | 24/9/2026 | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands. | |
| Analizada | Alta (8.1) | 22% | ⚠ Explotación activa | Craftcms Craft CMS | 18/1/2025 | 17/6/2026 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security… | |
| Analizada | Alta (7.2) | 65% | ⚠ Explotación activa💥 Exploit | Simple-help Simplehelp | 15/1/2025 | 17/6/2026 | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. | |
| Analizada | Alta (7.5) | 97% | ⚠ Explotación activa💥 Exploit | Simple-help Simplehelp | 15/1/2025 | 4/8/2026 | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed… | |
| Analizada | Crítica (9.9) | 67% | ⚠ Explotación activa💥 Exploit | Simple-help Simplehelp | 15/1/2025 | 17/6/2026 | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. | |
| Analizada | Alta (7.8) | 1.6% | ⚠ Explotación activa | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+3 | 14/1/2025 | 17/6/2026 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 10.0% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+3 | 14/1/2025 | 17/6/2026 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 90% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.5) | 91% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 14/1/2025 | 17/6/2026 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.8) | 1.4% | ⚠ Explotación activa | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+3 | 14/1/2025 | 24/9/2026 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | Fortinet FortiproxyFortinet Fortios | 14/1/2025 | 5/8/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Sonicwall Sonicos | 9/1/2025 | 4/8/2026 | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 8/1/2025 | 1/10/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Aviatrix Controller | 8/1/2025 | 17/6/2026 | An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for… |