Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)7.2%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+913/1/202630/7/2026
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
AnalizadaCrítica (9.8)3.9%⚠ Explotación activaFortinet FortiosFortinet FortiswitchmanagerFortinet FortisaseSiemens Ruggedcom Ape1808 Firmware13/1/202610/9/2026
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized…
AnalizadaMedia (6.1)17%⚠ Explotación activaSynacor Zimbra Collaboration Suite5/1/20267/10/2026
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.
AnalizadaCrítica (10)86%⚠ Explotación activa💥 ExploitSmartertools Smartermail29/12/20257/10/2026
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
AnalizadaAlta (8.8)49%⚠ Explotación activa💥 ExploitSynacor Zimbra Collaboration Suite22/12/202517/6/2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request…
AnalizadaAlta (8.8)99%⚠ Explotación activa💥 ExploitN8N19/12/202517/6/2026
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during…
AnalizadaAlta (8.7)83%⚠ Explotación activa💥 ExploitMongodb19/12/202517/6/2026
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0…
AnalizadaCrítica (9.3)27%⚠ Explotación activa💥 PoCWatchguard Fireware19/12/20259/9/2026
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was…
AnalizadaMedia (6.6)2.8%⚠ Explotación activa💥 PoCSonicwall Sma6200 FirmwareSonicwall Sma6210 FirmwareSonicwall Sma7200 FirmwareSonicwall Sma7210 Firmware+118/12/202517/6/2026
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
AnalizadaMedia (6.1)27%⚠ Explotación activa💥 PoCRoundcube Webmail18/12/202517/6/2026
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
AnalizadaAlta (8.8)8.8%⚠ Explotación activa💥 PoCApple SafariApple IpadosApple Iphone OSApple Macos+317/12/20257/10/2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of…
AnalizadaCrítica (10)32%⚠ Explotación activa💥 PoCCisco Asyncos17/12/202517/6/2026
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient…
AnalizadaCrítica (9.3)1.2%⚠ Explotación activaAsus Live Update17/12/202525/9/2026
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions…
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitHPE Oneview16/12/202517/6/2026
A remote code execution issue exists in HPE OneView.
AnalizadaAlta (7.1)53%⚠ Explotación activa💥 ExploitGladinet CentrestackGladinet Triofox12/12/202517/6/2026
Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without…
AnalizadaMedia (5.5)0.43%⚠ Explotación activaApple IpadosApple Iphone OSApple MacosApple Tvos+212/12/20257/10/2026
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system…
AnalizadaAlta (7.8)0.36%⚠ Explotación activaApple IpadosApple Iphone OSApple MacosApple Tvos+212/12/20257/10/2026
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory…
AnalizadaAlta (8.8)22%⚠ Explotación activa💥 PoCGoogle ChromeApple SafariApple IpadosApple Iphone OS+512/12/202530/9/2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
AnalizadaAlta (8.7)85%⚠ Explotación activa💥 ExploitGogs10/12/202517/6/2026
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
AnalizadaCrítica (9.8)68%⚠ Explotación activa💥 PoCFortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosSiemens Ruggedcom Ape1808 Firmware9/12/202517/6/2026
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through…
AnalizadaAlta (7.8)2.5%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+69/12/202525/9/2026
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.26%⚠ Explotación activaGoogle Android8/12/202530/9/2026
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaAlta (7.8)0.26%⚠ Explotación activaGoogle Android8/12/202530/9/2026
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AnalizadaCrítica (9.4)93%⚠ Explotación activa💥 ExploitLangflow5/12/202514/7/2026
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to…
AnalizadaCrítica (9.8)3.4%⚠ Explotación activaArraynetworks Arrayos AG5/12/202517/6/2026
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Orbitaley — Vulnerabilidades