Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa💥 Exploit | Samsung Magicinfo 9 Server | 12/8/2024 | 1/10/2026 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority. | |
| Analizada | Crítica (9.3) | 83% | ⚠ Explotación activa💥 Exploit | Roundcube Webmail | 5/8/2024 | 17/6/2026 | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Apache Ofbiz | 5/8/2024 | 17/6/2026 | Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the… | |
| Analizada | Crítica (9.8) | 53% | ⚠ Explotación activa💥 Exploit | Acronis Cyber Infrastructure | 24/7/2024 | 17/6/2026 | Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build… | |
| Analizada | Alta (7.5) | 74% | ⚠ Explotación activa💥 PoC | Oracle Weblogic Server | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… | |
| Analizada | Crítica (9.3) | 92% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Expedition | 10/7/2024 | 17/6/2026 | Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data… | |
| Analizada | Crítica (9.2) | 100% | ⚠ Explotación activa💥 Exploit | Servicenow | 10/7/2024 | 17/6/2026 | ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed… | |
| Analizada | Crítica (9.3) | 100% | ⚠ Explotación activa💥 Exploit | Servicenow | 10/7/2024 | 17/6/2026 | ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow… | |
| Analizada | Alta (7.5) | 84% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 9/7/2024 | 17/6/2026 | Windows MSHTML Platform Spoofing Vulnerability | |
| Analizada | Alta (7.2) | 51% | ⚠ Explotación activa | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 7.1% | ⚠ Explotación activa💥 PoC | Microsoft Windows 11 21h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2Microsoft Windows Server 2022+1 | 9/7/2024 | 17/6/2026 | Windows Hyper-V Elevation of Privilege Vulnerability | |
| Analizada | Media (5.3) | 1.7% | ⚠ Explotación activa | Twilio AuthyTwilio Authy Authenticator | 2/7/2024 | 17/6/2026 | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with… | |
| Analizada | Crítica (9.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache Http ServerNetapp Ontap 9Sonicwall SMA 200 FirmwareSonicwall SMA 210 Firmware+3 | 1/7/2024 | 17/6/2026 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in… | |
| Analizada | Media (6.7) | 4.3% | ⚠ Explotación activa💥 PoC | Cisco Nx-os | 1/7/2024 | 17/6/2026 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GeoserverGeotools | 1/7/2024 | 17/6/2026 | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Progress Whatsup Gold | 25/6/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges. | |
| Analizada | Alta (7.2) | 27% | ⚠ Explotación activa💥 PoC | Vmware Cloud FoundationVmware Esxi | 25/6/2024 | 17/6/2026 | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by… | |
| Analizada | Crítica (9.8) | 22% | ⚠ Explotación activa | Vmware Cloud FoundationVmware Vcenter Server | 18/6/2024 | 17/6/2026 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. | |
| Analizada | Crítica (9.8) | 10% | ⚠ Explotación activa | Geovision Gv-dsp LPR FirmwareGeovision Gv-bx130 FirmwareGeovision Gv-bx1500 FirmwareGeovision Gv-cb220 Firmware+16 | 17/6/2024 | 17/6/2026 | Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. | |
| Analizada | Alta (7.8) | 3.0% | ⚠ Explotación activa | Google Android | 13/6/2024 | 17/6/2026 | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Adobe CommerceAdobe Commerce WebhooksAdobe Magento | 13/6/2024 | 17/6/2026 | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external… | |
| Analizada | Alta (7.8) | 25% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 11/6/2024 | 20/7/2026 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | |
| Analizada | Alta (7) | 68% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+8 | 11/6/2024 | 4/8/2026 | Windows Kernel Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa💥 PoC | Debian LinuxLinux Kernel | 10/6/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | PHPFedoraproject Fedora | 9/6/2024 | 17/6/2026 | In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those… |