Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)54%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1110/9/202410/8/2026
Windows MSHTML Platform Spoofing Vulnerability
AnalizadaAlta (7.3)2.7%⚠ Explotación activaMicrosoft Office 2019Microsoft Office Long Term Servicing ChannelMicrosoft Publisher10/9/202410/8/2026
Microsoft Publisher Security Feature Bypass Vulnerability
AnalizadaMedia (5.4)10%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1110/9/202410/8/2026
Windows Mark of the Web Security Feature Bypass Vulnerability
AnalizadaAlta (7.8)6.3%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1110/9/202410/8/2026
Windows Installer Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitVeeam Backup & Replication7/9/202417/6/2026
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitCisco Smart License Utility4/9/202417/6/2026
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this…
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitApache Ofbiz4/9/202417/6/2026
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
AnalizadaCrítica (9.8)93%⚠ Explotación activa💥 ExploitProgress Whatsup Gold29/8/202417/6/2026
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
AnalizadaCrítica (9.8)18%⚠ Explotación activaSonicwall Sonicos23/8/202421/9/2026
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS…
AnalizadaAlta (7.2)4.0%⚠ Explotación activaVersa-networks Versa Director22/8/202417/6/2026
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be…
AnalizadaCrítica (9.1)93%⚠ Explotación activa💥 ExploitSolarwinds WEB Help Desk21/8/202417/6/2026
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
AnalizadaCrítica (9.6)21%⚠ Explotación activa💥 PoCGoogle ChromeMicrosoft Edge21/8/202417/6/2026
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)19%⚠ Explotación activa💥 PoCGoogle ChromeMicrosoft Edge Chromium21/8/202417/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaCrítica (9.3)2.9%⚠ Explotación activaKingsoft WPS Office15/8/202417/6/2026
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document
AnalizadaCrítica (9.8)85%⚠ Explotación activa💥 ExploitSolarwinds WEB Help Desk13/8/202417/6/2026
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitIvanti Virtual Traffic Manager13/8/202417/6/2026
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
AnalizadaMedia (6.5)14%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+913/8/202417/6/2026
Windows Mark of the Web Security Feature Bypass Vulnerability
AnalizadaAlta (7.8)29%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1113/8/202417/6/2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
AnalizadaAlta (8.8)8.2%⚠ Explotación activaMicrosoft 365 AppsMicrosoft Office 2019Microsoft Office Long Term Servicing ChannelMicrosoft Project 201613/8/202417/6/2026
Microsoft Project Remote Code Execution Vulnerability
AnalizadaAlta (7.5)41%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1013/8/202417/6/2026
Scripting Engine Memory Corruption Vulnerability
AnalizadaAlta (7.8)1.6%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1013/8/202417/6/2026
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
AnalizadaAlta (7)6.3%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+913/8/202417/6/2026
Windows Kernel Elevation of Privilege Vulnerability
AnalizadaAlta (7.2)42%⚠ Explotación activaMitel 6970 FirmwareMitel 6940w SIP FirmwareMitel 6930w SIP FirmwareMitel 6920w SIP Firmware+1112/8/202417/6/2026
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot…
AnalizadaMedia (6.1)24%⚠ Explotación activa💥 ExploitZimbra Collaboration12/8/202417/6/2026
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email…
AnalizadaAlta (7.2)1.8%⚠ Explotación activaTeamt5 Threatsonar Anti-ransomware12/8/202417/6/2026
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.