Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)98%⚠ Explotación activa💥 ExploitDraytek Vigor300b FirmwareDraytek Vigor2960 Firmware27/12/202417/6/2026
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible…
AnalizadaAlta (7.8)4.1%⚠ Explotación activaLinux KernelDebian Linux27/12/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to…
AnalizadaAlta (8.7)29%⚠ Explotación activaPaloaltonetworks Pan-osPaloaltonetworks Prisma Access27/12/202417/6/2026
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance…
AnalizadaAlta (7.1)1.4%⚠ Explotación activaDebian LinuxLinux Kernel24/12/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptor with a shorter…
AnalizadaCrítica (9.3)97%⚠ Explotación activa💥 ExploitCraftcms Craft CMS18/12/202417/6/2026
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised…
AnalizadaAlta (7.2)14%⚠ Explotación activaBeyondtrust Privileged Remote AccessBeyondtrust Remote Support18/12/202417/6/2026
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
AnalizadaCrítica (9.8)87%⚠ Explotación activa💥 ExploitBeyondtrust Privileged Remote AccessBeyondtrust Remote Support17/12/202417/6/2026
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
AnalizadaCrítica (9.8)94%⚠ Explotación activa💥 ExploitCleo HarmonyCleo LexicomCleo Vltrader13/12/20245/8/2026
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
AnalizadaAlta (7.8)26%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1112/12/202417/6/2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
AnalizadaBaja (2.7)38%⚠ Explotación activa💥 ExploitMitel Micollab10/12/20244/8/2026
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the…
AnalizadaAlta (7.8)3.4%⚠ Explotación activa💥 PoCDebian LinuxLinux Kernel2/12/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.
AnalizadaCrítica (9.8)2.9%⚠ Explotación activaZyxel ZLD27/11/20245/8/2026
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an…
AnalizadaCrítica (9.8)1.3%⚠ Explotación activaMicrosoft Partner Center26/11/202417/6/2026
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)92%⚠ Explotación activa💥 ExploitProjectsend26/11/202414/7/2026
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to…
AnalizadaMedia (6.3)23%⚠ Explotación activaDebian LinuxApple SafariApple IpadosApple Iphone OS+220/11/202417/6/2026
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a…
AnalizadaAlta (8.8)10%⚠ Explotación activa💥 PoCDebian LinuxApple SafariApple IpadosApple Iphone OS+220/11/202417/6/2026
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been…
AnalizadaMedia (5.5)0.81%⚠ Explotación activaGoogle AndroidDebian LinuxSiemens Simatic S7-1500 TM MFP FirmwareSiemens Sinec OS+119/11/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
AnalizadaAlta (7.5)1.7%⚠ Explotación activaOracle Agile Product Lifecycle Management18/11/202417/6/2026
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM…
AnalizadaMedia (6.9)95%⚠ Explotación activa💥 ExploitPaloaltonetworks Pan-os18/11/20244/8/2026
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
AnalizadaCrítica (9.3)100%⚠ Explotación activa💥 ExploitPaloaltonetworks Pan-os18/11/20244/8/2026
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation…
AnalizadaMedia (5.3)18%⚠ Explotación activaMdaemon15/11/202417/6/2026
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.
AnalizadaCrítica (9.8)28%⚠ Explotación activaGeovision Gv-vs12 FirmwareGeovision Gv-vs11 FirmwareGeovision Gv-dsp LPR FirmwareGeovision Gvlx 4 Firmware15/11/202417/6/2026
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
AnalizadaAlta (7.3)0.71%⚠ Explotación activaGoogle Android13/11/202417/6/2026
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed…
AnalizadaMedia (5.1)15%⚠ Explotación activa💥 PoCCitrix Session Recording12/11/202417/6/2026
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
AnalizadaMedia (5.1)3.5%⚠ Explotación activa💥 PoCCitrix Session Recording12/11/202417/6/2026
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
Orbitaley — Vulnerabilidades