Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)58%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/1/202417/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
AnalizadaAlta (8.8)3.2%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/1/202417/6/2026
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
AnalizadaAlta (8.8)3.8%⚠ Explotación activa💥 PoCGoogle ChromeFedoraproject FedoraCouchbase Server16/1/202417/6/2026
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitAtlassian Confluence Data CenterAtlassian Confluence Server16/1/202417/6/2026
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by…
AnalizadaCrítica (9.1)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Policy Secure12/1/20244/8/2026
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
AnalizadaAlta (8.2)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Policy Secure12/1/20241/10/2026
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 ExploitGitlab12/1/202417/6/2026
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email…
AnalizadaAlta (7.8)2.0%⚠ Explotación activaApple IpadosApple Iphone OS10/1/202417/6/2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.
AnalizadaAlta (7)0.49%⚠ Explotación activaApple IpadosApple Iphone OSApple MacosApple Tvos+19/1/202417/6/2026
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against…
AnalizadaAlta (7.8)10%⚠ Explotación activa💥 PoCLinux KernelCanonical Ubuntu Linux8/1/202420/8/2026
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
AnalizadaAlta (7.8)19%⚠ Explotación activa💥 ExploitJmcnamara Spreadsheet\Debian LinuxFedoraproject Fedora24/12/202317/6/2026
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings…
AnalizadaAlta (8.8)6.7%⚠ Explotación activa💥 PoCGoogle ChromeDebian LinuxFedoraproject Fedora21/12/202317/6/2026
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)73%⚠ Explotación activaQnap QVR Firmware8/12/202317/6/2026
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
AnalizadaAlta (8.8)50%⚠ Explotación activaFXC Ae1021 FirmwareFXC Ae1021pe Firmware6/12/202317/6/2026
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AnalizadaAlta (7.2)76%⚠ Explotación activaSonicwall SMA 200 FirmwareSonicwall SMA 210 FirmwareSonicwall SMA 400 FirmwareSonicwall SMA 410 Firmware+15/12/202317/6/2026
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
AnalizadaCrítica (9.8)2.1%⚠ Explotación activaUnitronics Vision1210 FirmwareUnitronics Vision1040 FirmwareUnitronics Vision700 FirmwareUnitronics Vision570 Firmware+135/12/202317/6/2026
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
AnalizadaAlta (7.8)0.74%⚠ Explotación activa💥 PoCQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+2385/12/202317/6/2026
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
AnalizadaAlta (7.8)0.79%⚠ Explotación activaQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1495/12/202317/6/2026
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
AnalizadaAlta (7.8)0.67%⚠ Explotación activaQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+2775/12/202317/6/2026
Memory corruption in DSP Services during a remote call from HLOS to DSP.
AnalizadaAlta (8.8)9.3%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+330/11/202317/6/2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before…
AnalizadaMedia (6.5)18%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+330/11/202317/6/2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS…
AnalizadaCrítica (9.6)16%⚠ Explotación activaGoogle ChromeDebian LinuxFedoraproject FedoraMicrosoft Edge Chromium29/11/202317/6/2026
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
AnalizadaCrítica (9.8)43%⚠ Explotación activa💥 PoCOwncloud Server21/11/202328/8/2026
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for…
AnalizadaAlta (7.5)78%⚠ Explotación activa💥 ExploitOwncloud Graph API21/11/202317/6/2026
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the…
AnalizadaCrítica (9.9)47%⚠ Explotación activaQlik Sense15/11/202317/6/2026
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts…
Orbitaley — Vulnerabilidades