Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Mobileiron Sentry | 21/8/2023 | 17/6/2026 | Una vulnerabilidad de seguridad en MICS Admin Portal en Ivanti MobileIron Sentry versiones 9.18.0 y anteriores, que puede permitir a un atacante eludir los controles de autenticación en la interfaz administrativa debido a una configuración insuficientemente restrictiva de Apache HTTPD . | |
| Analizada | Media (5.3) | 83% | ⚠ Explotación activa | Juniper Junos | 17/8/2023 | 17/6/2026 | — | |
| Analizada | Media (5.3) | 93% | ⚠ Explotación activa💥 PoC | Juniper Junos | 17/8/2023 | 17/6/2026 | — | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Juniper Junos | 17/8/2023 | 17/6/2026 | — | |
| Analizada | Media (5.3) | 90% | ⚠ Explotación activa💥 Exploit | Juniper Junos | 17/8/2023 | 17/6/2026 | — | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 15/8/2023 | 17/6/2026 | Una vulnerabilidad de omisión de autenticación en Ivanti EPMM 11.10 y versiones anteriores permite a usuarios no autorizados acceder a funciones o recursos restringidos de la aplicación sin la autenticación adecuada. Esta vulnerabilidad es exclusiva de CVE-2023-35078 anunciada anteriormente. | |
| Analizada | Alta (8.8) | 3.2% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+2 | 14/8/2023 | 17/6/2026 | El problema se solucionó con comprobaciones de límites mejoradas. Este problema se ha solucionado en tvOS 15.6, watchOS 8.7, iOS 15.6, iPadOS 15.6, macOS Monterey 12.5 and Safari 15.6. El procesamiento de contenido web puede dar lugar a la ejecución de código arbitrario. | |
| Analizada | Alta (7.5) | 14% | ⚠ Explotación activa | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022Fedoraproject Fedora | 8/8/2023 | 10/8/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Analizada | Alta (7.5) | 92% | ⚠ Explotación activa💥 Exploit | Zkteco Biotime | 3/8/2023 | 9/7/2026 | A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime. | |
| Analizada | Alta (7.2) | 64% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 3/8/2023 | 17/6/2026 | Una vulnerabilidad de path traversal en las versiones de Ivanti EPMM (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 y 11.8.x < 11.8.1.2) permite que un administrador autenticado escriba archivos arbitrarios en el dispositivo. | |
| Analizada | Media (6.1) | 49% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 31/7/2023 | 17/6/2026 | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. | |
| Analizada | Media (5.5) | 2.9% | ⚠ Explotación activa | Apple IpadosApple Iphone OSApple MacosApple Tvos+1 | 27/7/2023 | 17/6/2026 | This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this… | |
| Analizada | Alta (8.8) | 19% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 27/7/2023 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 25/7/2023 | 5/8/2026 | Una vulnerabilidad de omisión de autenticación en Ivanti EPMM permite a usuarios no autorizados acceder a funciones o recursos restringidos de la aplicación sin la autenticación adecuada. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Adobe Coldfusion | 20/7/2023 | 17/6/2026 | Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 5/8/2026 | Unauthenticated remote code execution | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Adobe Coldfusion | 12/7/2023 | 17/6/2026 | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Adobe Coldfusion | 12/7/2023 | 17/6/2026 | Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation… | |
| Analizada | Alta (7.5) | 99% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+8 | 11/7/2023 | 10/8/2026 | Windows Search Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 43% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+8 | 11/7/2023 | 17/6/2026 | Windows Error Reporting Service Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 4.2% | ⚠ Explotación activa | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+5 | 11/7/2023 | 17/6/2026 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| Analizada | Alta (7.8) | 10% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+8 | 11/7/2023 | 17/6/2026 | Windows MSHTML Platform Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 16% | ⚠ Explotación activa | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Outlook | 11/7/2023 | 8/10/2026 | Microsoft Outlook Security Feature Bypass Vulnerability | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Citrix Sharefile Storage Zones Controller | 10/7/2023 | 17/6/2026 | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | |
| Analizada | Crítica (9) | 77% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 6/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. |