Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.27%⚠ Explotación activaGoogle Android28/6/202317/6/2026
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
AnalizadaAlta (8.8)24%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+123/6/202317/6/2026
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been…
AnalizadaAlta (8.8)23%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos23/6/202317/6/2026
Se solucionó un problema de corrupción de memoria con una mejor gestión del estado. Este problema se solucionó en macOS Ventura 13.3, Safari 16.4, iOS 16.4 y iPadOS 16.4, iOS 15.7.7 y iPadOS 15.7.7. El procesamiento de contenido web puede provocar la ejecución de código arbitrario. Apple tiene conocimiento de un…
AnalizadaAlta (7.8)52%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple MacosApple Watchos23/6/202317/6/2026
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges.…
AnalizadaAlta (8.6)17%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+223/6/202317/6/2026
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been…
AnalizadaAlta (8.8)12%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+423/6/202317/6/2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that…
AnalizadaMedia (6.5)14%⚠ Explotación activaApple SafariApple IpadosApple Iphone OSApple Macos+323/6/202317/6/2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been…
AnalizadaAlta (8.8)29%⚠ Explotación activaPapercut MFPapercut NG20/6/202317/6/2026
Se ha identificado una vulnerabilidad de Cross-Site Request Forgery (CSRF) en PaperCut NG/MF que, en determinadas circunstancias, podría permitir a un atacante alterar la configuración de seguridad o ejecutar código arbitrario. Esto podría explotarse si el objetivo es un administrador con una sesión iniciada. Explotar…
AnalizadaCrítica (9.8)83%⚠ Explotación activaZyxel Nas326 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware19/6/202317/6/2026
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands…
AnalizadaAlta (8.4)22%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+514/6/202317/6/2026
Microsoft Streaming Service Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server14/6/202317/6/2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
AnalizadaBaja (3.9)14%⚠ Explotación activaVmware ToolsDebian LinuxFedoraproject Fedora13/6/202317/6/2026
Un host ESXi totalmente comprometido puede obligar a VMware Tools a no poder autenticar las operaciones de host a invitado, lo que afecta la confidencialidad y la integridad de la máquina virtual invitada.
AnalizadaCrítica (9.8)86%⚠ Explotación activa💥 PoCFortinet FortiproxyFortinet Fortios13/6/202331/7/2026
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may…
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitVmware Aria Operations FOR Networks7/6/202317/6/2026
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
AnalizadaAlta (8.8)42%⚠ Explotación activa💥 PoCTp-link Tl-wr940n FirmwareTp-link Tl-wr841n FirmwareTp-link Tl-wr740n Firmware7/6/202317/6/2026
Se ha descubierto que TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, y TL-WR740N V1/V2 contienen una vulnerabilidad de inyección de comandos en el componente /userRpm/WlanNetworkRpm.
AnalizadaAlta (8.8)32%⚠ Explotación activa💥 PoCGoogle ChromeFedoraproject FedoraDebian LinuxApple Macos+25/6/202317/6/2026
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitProgress Moveit CloudProgress Moveit Transfer2/6/202317/6/2026
En Progress MOVEit Transfer antes de 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5) y 2023.0.1 (15.0.1), se ha encontrado una vulnerabilidad de inyección SQL en la aplicación web MOVEit Transfer que podría permitir que un atacante no autenticado obtenga acceso a la base de datos de MOVEit…
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitIgniterealtime Openfire26/5/202317/6/2026
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an…
AnalizadaCrítica (9.8)88%⚠ Explotación activa💥 ExploitBarracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+124/5/202317/6/2026
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete…
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitApache Rocketmq24/5/202317/6/2026
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update…
AnalizadaCrítica (9.8)29%⚠ Explotación activaZyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp100w Firmware+1924/5/202317/6/2026
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series…
AnalizadaCrítica (9.8)28%⚠ Explotación activaZyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp100w Firmware+1924/5/202317/6/2026
Una vulnerabilidad de desbordamiento de búfer en la función de notificación en las versiones de firmware de la serie Zyxel ATP 4.60 a 5.36 Parche 1, versiones de firmware de la serie USG FLEX 4.60 a 5.36 Parche 1, versiones de firmware USG FLEX 50(W) 4.60 a 5.36 Parche 1, USG20(W)- Las versiones de firmware VPN 4.60 a…
AnalizadaAlta (7.8)41%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows Server 2008Microsoft Windows Server 2012+19/5/202317/6/2026
Win32k Elevation of Privilege Vulnerability
AnalizadaAlta (7.2)85%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server9/5/202317/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaMedia (4.4)2.6%⚠ Explotación activaSamsung Android4/5/202317/6/2026
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
Orbitaley — Vulnerabilidades