Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Dlink Dns-320l FirmwareDlink Dns-120 FirmwareDlink Dnr-202l FirmwareDlink Dns-315l Firmware+16 | 4/4/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the… | |
| Analizada | Alta (7.5) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft .net Framework | 23/3/2024 | 17/6/2026 | .NET Framework Information Disclosure Vulnerability | |
| Analizada | Alta (7.4) | 99% | ⚠ Explotación activa💥 Exploit | Adobe Coldfusion | 18/3/2024 | 17/6/2026 | ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of… | |
| Analizada | Alta (7.8) | 4.0% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 12/3/2024 | 17/6/2026 | Windows Error Reporting Service Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Fortinet Forticlient Enterprise Management Server | 12/3/2024 | 17/6/2026 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets. | |
| Analizada | Alta (7.8) | 1.4% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 5/3/2024 | 17/6/2026 | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able… | |
| Analizada | Alta (7.8) | 1.5% | ⚠ Explotación activa | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 5/3/2024 | 17/6/2026 | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able… | |
| Analizada | Alta (7.3) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 4/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Jetbrains Teamcity | 4/3/2024 | 17/6/2026 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Progress Loadmaster | 21/2/2024 | 13/7/2026 | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Connectwise Screenconnect | 21/2/2024 | 17/6/2026 | ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems. | |
| Analizada | Alta (8.4) | 95% | ⚠ Explotación activa💥 Exploit | Connectwise Screenconnect | 21/2/2024 | 17/6/2026 | ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems. | |
| Analizada | Alta (8.8) | 3.9% | ⚠ Explotación activa | Oracle Agile Product Lifecycle Management | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in… | |
| Analizada | Crítica (9.8) | 62% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosFortinet Fortipam | 15/2/2024 | 17/6/2026 | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions… | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 PoC | Microsoft 365 AppsMicrosoft Office 2016Microsoft Office 2019Microsoft Office Long Term Servicing Channel | 13/2/2024 | 10/8/2026 | Microsoft Outlook Remote Code Execution Vulnerability | |
| Analizada | Alta (8.1) | 99% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 21h2+5 | 13/2/2024 | 10/8/2026 | Internet Shortcut Files Security Feature Bypass Vulnerability | |
| Analizada | Crítica (9.8) | 13% | ⚠ Explotación activa💥 PoC | Microsoft Exchange Server | 13/2/2024 | 17/6/2026 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.6) | 28% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+8 | 13/2/2024 | 10/8/2026 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| Analizada | Alta (7.8) | 60% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 21h2+5 | 13/2/2024 | 10/8/2026 | Windows Kernel Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 83% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet Fortios | 9/2/2024 | 4/8/2026 | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0… | |
| Analizada | Alta (8.2) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Policy SecureIvanti Neurons FOR Zero-trust Access | 31/1/2024 | 4/8/2026 | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication. | |
| Analizada | Alta (7.8) | 28% | ⚠ Explotación activa💥 PoC | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+14 | 31/1/2024 | 7/8/2026 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Jenkins | 24/1/2024 | 17/6/2026 | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. | |
| Analizada | Alta (8.8) | 11% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 23/1/2024 | 17/6/2026 | A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may… | |
| Analizada | Crítica (9.8) | 83% | ⚠ Explotación activa | Dlink Dir-859 Firmware | 21/1/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input… |