Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Facebook ReactVercel Next.js | 3/12/2025 | 7/10/2026 | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP… | |
| Analizada | Crítica (9.4) | 62% | ⚠ Explotación activa💥 Exploit | Anyscale RAY | 26/11/2025 | 1/10/2026 | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent… | |
| Analizada | Crítica (9.8) | 61% | ⚠ Explotación activa💥 Exploit | Geoserver | 25/11/2025 | 17/6/2026 | GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input… | |
| Analizada | Alta (7.2) | 56% | ⚠ Explotación activa💥 Exploit | Fortinet Fortiweb | 18/11/2025 | 17/6/2026 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an… | |
| Analizada | Alta (8.8) | 5.0% | ⚠ Explotación activa | Google ChromeSiemens Cadra | 17/11/2025 | 14/7/2026 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa💥 Exploit | Fortinet Fortiweb | 14/11/2025 | 17/6/2026 | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests. | |
| Analizada | Alta (7) | 6.0% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+6 | 11/11/2025 | 17/6/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 4.6% | ⚠ Explotación activa💥 PoC | Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows Server 2025 | 11/11/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.1) | 95% | ⚠ Explotación activa💥 Exploit | Gladinet Triofox | 10/11/2025 | 17/6/2026 | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete. | |
| Analizada | Alta (8.6) | 85% | ⚠ Explotación activa💥 Exploit | Sangoma Filestore | 7/11/2025 | 17/6/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection ->… | |
| Analizada | Alta (8.8) | 4.0% | ⚠ Explotación activa | Apple SafariApple IpadosApple Iphone OSApple Macos | 5/11/2025 | 21/9/2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption. | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | React-native-community React Native Community CLI | 3/11/2025 | 17/6/2026 | The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On… | |
| Analizada | Crítica (9.8) | 89% | ⚠ Explotación activa💥 Exploit | Oracle Identity Manager | 21/10/2025 | 17/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks… | |
| Analizada | Crítica (9.3) | 2.8% | ⚠ Explotación activa | Motex Lanscope Endpoint Manager | 20/10/2025 | 17/6/2026 | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets. | |
| Analizada | Crítica (9.3) | 2.3% | ⚠ Explotación activa | F5 Big-ip Access Policy Manager | 15/10/2025 | 17/6/2026 | When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019Microsoft Windows Server 2022+2 | 14/10/2025 | 17/6/2026 | Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+12 | 14/10/2025 | 17/6/2026 | Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 6.4% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+12 | 14/10/2025 | 17/6/2026 | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific… | |
| Analizada | Media (5.5) | 1.3% | ⚠ Explotación activa💥 PoC | Linux KernelSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP Firmware | 13/10/2025 | 19/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal… | |
| Analizada | Alta (7.5) | 96% | ⚠ Explotación activa💥 Exploit | Oracle Configurator | 12/10/2025 | 4/8/2026 | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this… | |
| Analizada | Alta (7.5) | 92% | ⚠ Explotación activa💥 Exploit | Gladinet CentrestackGladinet Triofox | 9/10/2025 | 17/6/2026 | In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Oracle Concurrent Processing | 5/10/2025 | 4/8/2026 | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing.… | |
| Analizada | Alta (7.8) | 8.4% | ⚠ Explotación activa💥 PoC | Vmware Aria OperationsVmware Cloud FoundationVmware Cloud Foundation OperationsVmware Open VM Tools+4 | 29/9/2025 | 17/6/2026 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the… | |
| Analizada | Alta (8.6) | 87% | ⚠ Explotación activa💥 Exploit | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 25/9/2025 | 11/8/2026 | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS)… | |
| Analizada | Crítica (9.9) | 71% | ⚠ Explotación activa💥 PoC | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 25/9/2025 | 11/8/2026 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of… |