Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 7.2% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 13/1/2026 | 30/7/2026 | Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | |
| Analizada | Crítica (9.8) | 3.9% | ⚠ Explotación activa | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortisaseSiemens Ruggedcom Ape1808 Firmware | 13/1/2026 | 10/9/2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized… | |
| Analizada | Media (6.1) | 17% | ⚠ Explotación activa | Synacor Zimbra Collaboration Suite | 5/1/2026 | 7/10/2026 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. | |
| Analizada | Crítica (10) | 86% | ⚠ Explotación activa💥 Exploit | Smartertools Smartermail | 29/12/2025 | 7/10/2026 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. | |
| Analizada | Alta (8.8) | 49% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 22/12/2025 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request… | |
| Analizada | Alta (8.8) | 99% | ⚠ Explotación activa💥 Exploit | N8N | 19/12/2025 | 17/6/2026 | n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during… | |
| Analizada | Alta (8.7) | 83% | ⚠ Explotación activa💥 Exploit | Mongodb | 19/12/2025 | 17/6/2026 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0… | |
| Analizada | Crítica (9.3) | 27% | ⚠ Explotación activa💥 PoC | Watchguard Fireware | 19/12/2025 | 9/9/2026 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was… | |
| Analizada | Media (6.6) | 2.8% | ⚠ Explotación activa💥 PoC | Sonicwall Sma6200 FirmwareSonicwall Sma6210 FirmwareSonicwall Sma7200 FirmwareSonicwall Sma7210 Firmware+1 | 18/12/2025 | 17/6/2026 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). | |
| Analizada | Media (6.1) | 27% | ⚠ Explotación activa💥 PoC | Roundcube Webmail | 18/12/2025 | 17/6/2026 | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. | |
| Analizada | Alta (8.8) | 8.8% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+3 | 17/12/2025 | 7/10/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of… | |
| Analizada | Crítica (10) | 32% | ⚠ Explotación activa💥 PoC | Cisco Asyncos | 17/12/2025 | 17/6/2026 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient… | |
| Analizada | Crítica (9.3) | 1.2% | ⚠ Explotación activa | Asus Live Update | 17/12/2025 | 25/9/2026 | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions… | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa💥 Exploit | HPE Oneview | 16/12/2025 | 17/6/2026 | A remote code execution issue exists in HPE OneView. | |
| Analizada | Alta (7.1) | 53% | ⚠ Explotación activa💥 Exploit | Gladinet CentrestackGladinet Triofox | 12/12/2025 | 17/6/2026 | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without… | |
| Analizada | Media (5.5) | 0.43% | ⚠ Explotación activa | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 12/12/2025 | 7/10/2026 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system… | |
| Analizada | Alta (7.8) | 0.36% | ⚠ Explotación activa | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 12/12/2025 | 7/10/2026 | A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory… | |
| Analizada | Alta (8.8) | 22% | ⚠ Explotación activa💥 PoC | Google ChromeApple SafariApple IpadosApple Iphone OS+5 | 12/12/2025 | 30/9/2026 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.7) | 85% | ⚠ Explotación activa💥 Exploit | Gogs | 10/12/2025 | 17/6/2026 | Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. | |
| Analizada | Crítica (9.8) | 68% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosSiemens Ruggedcom Ape1808 Firmware | 9/12/2025 | 17/6/2026 | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through… | |
| Analizada | Alta (7.8) | 2.5% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+6 | 9/12/2025 | 25/9/2026 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.5) | 0.26% | ⚠ Explotación activa | Google Android | 8/12/2025 | 30/9/2026 | In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.26% | ⚠ Explotación activa | Google Android | 8/12/2025 | 30/9/2026 | In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Crítica (9.4) | 93% | ⚠ Explotación activa💥 Exploit | Langflow | 5/12/2025 | 14/7/2026 | Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to… | |
| Analizada | Crítica (9.8) | 3.4% | ⚠ Explotación activa | Arraynetworks Arrayos AG | 5/12/2025 | 17/6/2026 | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. |