Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitDlink Dns-320l FirmwareDlink Dns-120 FirmwareDlink Dnr-202l FirmwareDlink Dns-315l Firmware+164/4/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the…
AnalizadaAlta (7.5)99%⚠ Explotación activa💥 ExploitMicrosoft .net Framework23/3/202417/6/2026
.NET Framework Information Disclosure Vulnerability
AnalizadaAlta (7.4)99%⚠ Explotación activa💥 ExploitAdobe Coldfusion18/3/202417/6/2026
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of…
AnalizadaAlta (7.8)4.0%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1012/3/202417/6/2026
Windows Error Reporting Service Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitFortinet Forticlient Enterprise Management Server12/3/202417/6/2026
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
AnalizadaAlta (7.8)1.4%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple MacosApple Tvos+25/3/202417/6/2026
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able…
AnalizadaAlta (7.8)1.5%⚠ Explotación activaApple IpadosApple Iphone OSApple MacosApple Tvos+25/3/202417/6/2026
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able…
AnalizadaAlta (7.3)100%⚠ Explotación activa💥 ExploitJetbrains Teamcity4/3/202417/6/2026
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitJetbrains Teamcity4/3/202417/6/2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 ExploitProgress Loadmaster21/2/202413/7/2026
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitConnectwise Screenconnect21/2/202417/6/2026
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.
AnalizadaAlta (8.4)95%⚠ Explotación activa💥 ExploitConnectwise Screenconnect21/2/202417/6/2026
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
AnalizadaAlta (8.8)3.9%⚠ Explotación activaOracle Agile Product Lifecycle Management17/2/202417/6/2026
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in…
AnalizadaCrítica (9.8)62%⚠ Explotación activa💥 PoCFortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosFortinet Fortipam15/2/202417/6/2026
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions…
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 PoCMicrosoft 365 AppsMicrosoft Office 2016Microsoft Office 2019Microsoft Office Long Term Servicing Channel13/2/202410/8/2026
Microsoft Outlook Remote Code Execution Vulnerability
AnalizadaAlta (8.1)99%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 21h2+513/2/202410/8/2026
Internet Shortcut Files Security Feature Bypass Vulnerability
AnalizadaCrítica (9.8)13%⚠ Explotación activa💥 PoCMicrosoft Exchange Server13/2/202417/6/2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
AnalizadaAlta (7.6)28%⚠ Explotación activaMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+813/2/202410/8/2026
Windows SmartScreen Security Feature Bypass Vulnerability
AnalizadaAlta (7.8)60%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 21h2+513/2/202410/8/2026
Windows Kernel Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)83%⚠ Explotación activa💥 PoCFortinet FortiproxyFortinet Fortios9/2/20244/8/2026
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0…
AnalizadaAlta (8.2)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Policy SecureIvanti Neurons FOR Zero-trust Access31/1/20244/8/2026
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
AnalizadaAlta (7.8)28%⚠ Explotación activa💥 PoCNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+1431/1/20247/8/2026
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitJenkins24/1/202417/6/2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
AnalizadaAlta (8.8)11%⚠ Explotación activa💥 PoCApple SafariApple IpadosApple Iphone OSApple Macos+223/1/202417/6/2026
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may…
AnalizadaCrítica (9.8)83%⚠ Explotación activaDlink Dir-859 Firmware21/1/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input…