Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 54% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 10/9/2024 | 10/8/2026 | Windows MSHTML Platform Spoofing Vulnerability | |
| Analizada | Alta (7.3) | 2.7% | ⚠ Explotación activa | Microsoft Office 2019Microsoft Office Long Term Servicing ChannelMicrosoft Publisher | 10/9/2024 | 10/8/2026 | Microsoft Publisher Security Feature Bypass Vulnerability | |
| Analizada | Media (5.4) | 10% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 10/9/2024 | 10/8/2026 | Windows Mark of the Web Security Feature Bypass Vulnerability | |
| Analizada | Alta (7.8) | 6.3% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 10/9/2024 | 10/8/2026 | Windows Installer Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa💥 Exploit | Veeam Backup & Replication | 7/9/2024 | 17/6/2026 | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Cisco Smart License Utility | 4/9/2024 | 17/6/2026 | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Apache Ofbiz | 4/9/2024 | 17/6/2026 | Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. | |
| Analizada | Crítica (9.8) | 93% | ⚠ Explotación activa💥 Exploit | Progress Whatsup Gold | 29/8/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | |
| Analizada | Crítica (9.8) | 18% | ⚠ Explotación activa | Sonicwall Sonicos | 23/8/2024 | 21/9/2026 | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS… | |
| Analizada | Alta (7.2) | 4.0% | ⚠ Explotación activa | Versa-networks Versa Director | 22/8/2024 | 17/6/2026 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be… | |
| Analizada | Crítica (9.1) | 93% | ⚠ Explotación activa💥 Exploit | Solarwinds WEB Help Desk | 21/8/2024 | 17/6/2026 | The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. | |
| Analizada | Crítica (9.6) | 21% | ⚠ Explotación activa💥 PoC | Google ChromeMicrosoft Edge | 21/8/2024 | 17/6/2026 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 19% | ⚠ Explotación activa💥 PoC | Google ChromeMicrosoft Edge Chromium | 21/8/2024 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.3) | 2.9% | ⚠ Explotación activa | Kingsoft WPS Office | 15/8/2024 | 17/6/2026 | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document | |
| Analizada | Crítica (9.8) | 85% | ⚠ Explotación activa💥 Exploit | Solarwinds WEB Help Desk | 13/8/2024 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Virtual Traffic Manager | 13/8/2024 | 17/6/2026 | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel. | |
| Analizada | Media (6.5) | 14% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+9 | 13/8/2024 | 17/6/2026 | Windows Mark of the Web Security Feature Bypass Vulnerability | |
| Analizada | Alta (7.8) | 29% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 13/8/2024 | 17/6/2026 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 8.2% | ⚠ Explotación activa | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office Long Term Servicing ChannelMicrosoft Project 2016 | 13/8/2024 | 17/6/2026 | Microsoft Project Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 41% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 13/8/2024 | 17/6/2026 | Scripting Engine Memory Corruption Vulnerability | |
| Analizada | Alta (7.8) | 1.6% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 13/8/2024 | 17/6/2026 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | |
| Analizada | Alta (7) | 6.3% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+9 | 13/8/2024 | 17/6/2026 | Windows Kernel Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.2) | 42% | ⚠ Explotación activa | Mitel 6970 FirmwareMitel 6940w SIP FirmwareMitel 6930w SIP FirmwareMitel 6920w SIP Firmware+11 | 12/8/2024 | 17/6/2026 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot… | |
| Analizada | Media (6.1) | 24% | ⚠ Explotación activa💥 Exploit | Zimbra Collaboration | 12/8/2024 | 17/6/2026 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email… | |
| Analizada | Alta (7.2) | 1.8% | ⚠ Explotación activa | Teamt5 Threatsonar Anti-ransomware | 12/8/2024 | 17/6/2026 | ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server. |