Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2699▼ 343 respecto a la semana anterior
Críticas / altas1270▼ 197 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)208▼ 123 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)64%⚠ Explotación activaNetapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+125/4/202317/6/2026
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitZyxel Atp100 FirmwareZyxel Atp100w FirmwareZyxel Atp200 FirmwareZyxel Atp500 Firmware+1525/4/202317/6/2026
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS…
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitApache Superset24/4/202317/6/2026
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitPapercut MFPapercut NG20/4/202317/6/2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can…
AnalizadaAlta (7.5)78%⚠ Explotación activa💥 ExploitPapercut MFPapercut NG20/4/20231/10/2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the…
AnalizadaCrítica (9.6)5.7%⚠ Explotación activaGoogle ChromeDebian LinuxFedoraproject Fedora19/4/202317/6/2026
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.8)41%⚠ Explotación activa💥 PoCGoogle ChromeDebian LinuxFedoraproject FedoraCouchbase Server14/4/202317/6/2026
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (7.2)54%⚠ Explotación activaCisco Rv016 FirmwareCisco Rv042 FirmwareCisco Rv042g FirmwareCisco Rv082 Firmware+213/4/202317/6/2026
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming…
AnalizadaAlta (7.8)49%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 20h2+911/4/202317/6/2026
Vulnerabilidad de Elevación de Privilegios de Windows Common Log File System Driver
AnalizadaAlta (7)1.7%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 20h2+911/4/202317/6/2026
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)2.7%⚠ Explotación activa3rdmill Novi Survey11/4/202317/6/2026
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
AnalizadaAlta (8.6)23%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple Macos10/4/202317/6/2026
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a…
AnalizadaAlta (8.8)27%⚠ Explotación activa💥 PoCApple SafariApple IpadosApple Iphone OSApple Macos10/4/202317/6/2026
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may…
AnalizadaBaja (3.3)1.2%⚠ Explotación activa💥 PoCARM 5TH GEN GPU Architecture Kernel DriverARM Bifrost GPU Kernel DriverARM Midgard GPU Kernel DriverARM Valhall GPU Kernel Driver6/4/202317/6/2026
La vulnerabilidad de pérdida de memoria en el controlador del kernel de GPU de Mali en el controlador del kernel de GPU de Midgard todas las versiones de r6p0 a r32p0, el controlador del kernel de GPU de Bifrost todas las versiones de r0p0 a r42p0, el controlador del kernel de GPU de Valhall todas las versiones de…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitSophos WEB Appliance4/4/202317/6/2026
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
AnalizadaCrítica (9.8)92%⚠ Explotación activa💥 ExploitHitachi Vantara Pentaho Business Analytics Server3/4/202317/6/2026
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
AnalizadaAlta (7.2)98%⚠ Explotación activa💥 ExploitHitachi Vantara Pentaho Business Analytics Server3/4/202317/6/2026
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
AnalizadaAlta (7.8)1.5%⚠ Explotación activa💥 PoCGoogle Android24/3/202317/6/2026
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
AnalizadaCrítica (9.8)2.7%⚠ Explotación activaHelpsystems Cobalt Strike24/3/202317/6/2026
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitAdobe Coldfusion23/3/202317/6/2026
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
AnalizadaCrítica (9.8)17%⚠ Explotación activaAdobe Coldfusion23/3/202317/6/2026
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
AnalizadaAlta (8.8)7.9%⚠ Explotación activa💥 PoCMinio22/3/202317/6/2026
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*`…
AnalizadaAlta (7.5)84%⚠ Explotación activa💥 ExploitMinio22/3/202317/6/2026
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed…
AnalizadaAlta (7.8)7.9%⚠ Explotación activa💥 ExploitDebian LinuxNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+422/3/202317/6/2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on…
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitDlink Dir-820l Firmware16/3/202317/6/2026
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.