Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.76% | ⚠ Explotación activa | ARM Bifrost GPU Kernel DriverARM Valhall GPU Kernel Driver | 7/6/2024 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel… | |
| Analizada | Media (6.1) | 73% | ⚠ Explotación activa💥 Exploit | Roundcube WebmailDebian Linux | 7/6/2024 | 17/6/2026 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Solarwinds Serv-u | 6/6/2024 | 17/6/2026 | SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 31/5/2024 | 17/6/2026 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Rejetto Http File Server | 31/5/2024 | 11/8/2026 | Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Telerik Report Server 2024 | 29/5/2024 | 17/6/2026 | In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability. | |
| Analizada | Alta (8.6) | 100% | ⚠ Explotación activa💥 Exploit | Checkpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security | 28/5/2024 | 5/8/2026 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. | |
| Analizada | Crítica (9.6) | 7.5% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject Fedora | 28/5/2024 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.7) | 27% | ⚠ Explotación activa | Javs Viewer | 23/5/2024 | 17/6/2026 | Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands. | |
| Analizada | Crítica (9.6) | 15% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject Fedora | 15/5/2024 | 17/6/2026 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (7.8) | 5.7% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+7 | 14/5/2024 | 17/6/2026 | Windows DWM Core Library Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 3.9% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+8 | 14/5/2024 | 17/6/2026 | Windows MSHTML Platform Security Feature Bypass Vulnerability | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 8.3% | ⚠ Explotación activa | Google ChromeFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache Ofbiz | 8/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue. | |
| Analizada | Media (6.5) | 16% | ⚠ Explotación activa | Tp-link Tl-wr841n FirmwareTp-link Mr6400 FirmwareTp-link Tl-wdr3600 FirmwareTp-link Tl-wdr4300 Firmware+32 | 3/5/2024 | 3/9/2026 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (6) | 19% | ⚠ Explotación activa | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 24/4/2024 | 11/8/2026 | A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level… | |
| Analizada | Alta (8.6) | 71% | ⚠ Explotación activa | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 24/4/2024 | 11/8/2026 | A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Crushftp | 22/4/2024 | 17/6/2026 | A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Apache Hugegraph | 22/4/2024 | 17/6/2026 | RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-os | 12/4/2024 | 17/6/2026 | A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW,… | |
| Analizada | Alta (8.8) | 45% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 21h2+5 | 9/4/2024 | 17/6/2026 | SmartScreen Prompt Security Feature Bypass Vulnerability | |
| Analizada | Alta (7.8) | 0.67% | ⚠ Explotación activa | Google Android | 5/4/2024 | 17/6/2026 | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Media (5.5) | 0.48% | ⚠ Explotación activa | Google Android | 5/4/2024 | 17/6/2026 | there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Dlink Dns-320l FirmwareDlink Dns-120 FirmwareDlink Dnr-202l FirmwareDlink Dns-315l Firmware+16 | 4/4/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads… |