Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 1.4% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/2/2026 | 17/6/2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been… | |
| Analizada | Alta (7.8) | 4.1% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 10/2/2026 | 17/6/2026 | Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.2) | 4.8% | ⚠ Explotación activa | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 10/2/2026 | 17/6/2026 | Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. | |
| Analizada | Alta (7.8) | 2.5% | ⚠ Explotación activa | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 10/2/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 1.6% | ⚠ Explotación activa💥 PoC | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 10/2/2026 | 17/6/2026 | Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 16% | ⚠ Explotación activa | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 10/2/2026 | 17/6/2026 | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 10/2/2026 | 17/6/2026 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.5) | 88% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager | 10/2/2026 | 17/6/2026 | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. | |
| Analizada | Media (5.9) | 30% | ⚠ Explotación activa | Fortinet Fortios | 10/2/2026 | 28/7/2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch… | |
| Analizada | Crítica (9.9) | 91% | ⚠ Explotación activa💥 Exploit | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 6/2/2026 | 17/6/2026 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | Fortinet Forticlientems | 6/2/2026 | 17/6/2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | |
| Analizada | Alta (7.7) | 1.8% | ⚠ Explotación activa💥 PoC | Notepad-plus-plus Notepad++ | 3/2/2026 | 17/6/2026 | Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa💥 Exploit | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | |
| Analizada | Crítica (9.8) | 74% | ⚠ Explotación activa💥 Exploit | Solarwinds WEB Help Desk | 28/1/2026 | 17/6/2026 | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality. | |
| Analizada | Crítica (9.8) | 86% | ⚠ Explotación activa💥 PoC | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortinac-fFortinet Fortiproxy+3 | 27/1/2026 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9,… | |
| Analizada | Alta (7.8) | 71% | ⚠ Explotación activa💥 PoC | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 26/1/2026 | 25/6/2026 | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Crítica (9.3) | 88% | ⚠ Explotación activa💥 Exploit | Smartertools Smartermail | 23/1/2026 | 4/8/2026 | SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application. | |
| Analizada | Crítica (9.8) | 63% | ⚠ Explotación activa💥 Exploit | Langflow | 23/1/2026 | 22/7/2026 | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Crítica (9.3) | 97% | ⚠ Explotación activa💥 Exploit | Smartertools Smartermail | 22/1/2026 | 4/8/2026 | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated… | |
| Analizada | Crítica (9.8) | 4.5% | ⚠ Explotación activa💥 PoC | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 21/1/2026 | 17/6/2026 | — | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | GNU InetutilsDebian Linux | 21/1/2026 | 30/9/2026 | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. | |
| Analizada | Crítica (10) | 73% | ⚠ Explotación activa💥 PoC | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 20/1/2026 | 25/8/2026 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable… | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa | Microsoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |