Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Symantec Data Loss Prevention Windows EndpointAI | 30/3/2026 | 17/6/2026 | Symantec Data Loss Prevention Windows Endpoint, anterior a 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12 y 16.0 MP2 HF15, puede ser susceptible a una vulnerabilidad de Elevación de Privilegios, que es un tipo de problema mediante el cual un atacante puede intentar comprometer la aplicación de software para… | |
| Aplazada | Alta (7.5) | 0.43% | — | Multidots Fraud Prevention FOR WoocommerceAI | 19/3/2026 | 17/6/2026 | Vulnerabilidad de Autorización Faltante en Dotstore Fraud Prevention For Woocommerce permite la Explotación de Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a Fraud Prevention For Woocommerce: desde n/a hasta 2.3.3. | |
| Analizada | Media (5.8) | 0.43% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 18/8/2026 | Múltiples productos Cisco se ven afectados por una vulnerabilidad en el motor de detección de Snort 3 que podría permitir a un atacante remoto no autenticado provocar el reinicio del motor de detección de Snort 3, lo que resultaría en una interrupción de la inspección de paquetes. Esta vulnerabilidad se debe a una… | |
| Analizada | Media (5.8) | 0.47% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 19/8/2026 | Múltiples productos Cisco se ven afectados por una vulnerabilidad en el motor de detección de Snort 3 que podría permitir a un atacante remoto no autenticado provocar el reinicio del motor de detección de Snort 3, lo que resultaría en una interrupción de la inspección de paquetes. Esta vulnerabilidad se debe a una… | |
| Analizada | Media (5.8) | 0.47% | — | Cisco SnortCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 19/8/2026 | Múltiples productos Cisco se ven afectados por una vulnerabilidad en el motor de detección Snort 3 que podría permitir a un atacante remoto no autenticado provocar el reinicio del motor de detección Snort 3, lo que resultaría en una interrupción de la inspección de paquetes. Esta vulnerabilidad se debe a un error en… | |
| Analizada | Media (5.8) | 0.38% | — | Cisco SnortCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 19/8/2026 | Múltiples productos Cisco se ven afectados por una vulnerabilidad en el motor de detección Snort 3 que podría permitir a un atacante remoto no autenticado provocar que el motor de detección Snort 3 se reinicie, lo que resultaría en una interrupción de la inspección de paquetes. Esta vulnerabilidad se debe a un error… | |
| Analizada | Media (5.8) | 0.40% | — | Cisco SnortCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 20/8/2026 | Múltiples productos Cisco se ven afectados por vulnerabilidades en la característica VBA de Snort 3 que podrían permitir a un atacante remoto no autenticado provocar la caída del motor de detección de Snort 3. Estas vulnerabilidades se deben a una comprobación de errores incorrecta al descomprimir datos VBA. Un… | |
| Analizada | Media (5.8) | 0.45% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 20/8/2026 | Múltiples productos Cisco se ven afectados por una vulnerabilidad en la característica de Visual Basic para Aplicaciones (VBA) de Snort 3 que podría permitir a un atacante remoto no autenticado causar la caída del motor de detección de Snort 3. Esta vulnerabilidad se debe a la falta de una comprobación de errores… | |
| Analizada | Media (5.8) | 0.45% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 20/8/2026 | Múltiples productos de Cisco se ven afectados por una vulnerabilidad en la característica VBA de Snort 3 que podría permitir a un atacante remoto no autenticado provocar la caída del motor de detección de Snort 3. Esta vulnerabilidad se debe a una comprobación de errores incorrecta al descomprimir datos VBA. Un… | |
| Analizada | Media (5.8) | 0.43% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 20/8/2026 | Múltiples productos Cisco están afectados por una vulnerabilidad en la característica VBA de Snort 3 que podría permitir a un atacante remoto no autenticado provocar la caída del motor de detección de Snort 3. Esta vulnerabilidad se debe a una comprobación de rango incorrecta al descomprimir datos VBA, que son… | |
| Analizada | Media (5.8) | 0.51% | — | Cisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System EngineCisco Snort | 4/3/2026 | 1/9/2026 | Múltiples productos Cisco están afectados por una vulnerabilidad en el motor de detección Snort 3 que podría permitir a un atacante remoto no autenticado provocar el reinicio del motor de detección Snort 3, lo que resultaría en una interrupción de la inspección de paquetes. Esta vulnerabilidad se debe a un análisis… | |
| Aplazada | Media (4.3) | 0.25% | — | Multidots Fraud Prevention FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Vulnerabilidad de Exposición de Información Sensible del Sistema a una Esfera de Control No Autorizada en Dotstore Fraud Prevention para Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers permite Recuperar Datos Sensibles Incrustados. Este problema afecta a Fraud Prevention para… | |
| Analizada | Alta (7.8) | 0.21% | — | Forcepoint ONE Data Loss Prevention | 6/1/2026 | 17/6/2026 | Cliente Forcepoint One DLP, versión 23.04.5642 (y posiblemente versiones más recientes), incluye una versión restringida de Python 2.5.4 que impide el uso de la biblioteca ctypes. ctypes es una interfaz de función externa (FFI) para Python, lo que permite llamadas a DLLs/bibliotecas compartidas, asignación de memoria… | |
| Analizada | Media (5.5) | 0.56% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability affects unknown code of the file uploadWxFile.do. The manipulation of the argument File results in unrestricted upload. The attack may be performed from remote. The exploit has been released to… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A vulnerability was identified in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This affects the function findRolePage of the file findSingConfigPage.do. The manipulation of the argument sort leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A vulnerability was determined in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this issue is the function findCategoryPage of the file findCategoryPage.do. Executing manipulation of the argument tenantId can lead to sql injection. The attack can be executed remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A vulnerability was found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this vulnerability is the function findUserPage of the file findUserPage.do. Performing manipulation of the argument sort results in sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A vulnerability has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected is the function findRolePage of the file findSingConfigPage.do. Such manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A flaw has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This impacts the function findRolePage of the file findRolePage.do. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. The vendor… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A vulnerability was detected in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This affects the function findModulePage of the file findModulePage.do. The manipulation of the argument sort results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. The… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A security vulnerability has been detected in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. The impacted element is the function findTenantPage of the file findTenantPage.do. The manipulation of the argument sort leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 6/10/2025 | 17/6/2026 | A weakness has been identified in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. The affected element is the function findFileServerPage of the file findFileServerPage.do. Executing manipulation of the argument sort can lead to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.5) | 0.50% | — | Tipray Data Leakage Prevention System | 5/10/2025 | 17/6/2026 | A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Impacted is the function doFilter of the file findDeptPage.do. Performing manipulation of the argument sort results in sql injection. It is possible to initiate the attack remotely. The exploit has been released… | |
| Analizada | Alta (7.5) | 1.5% | — | Cisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 15/11/2024 | 11/8/2026 | Una vulnerabilidad en el preprocesador Modbus del motor de detección Snort podría permitir que un atacante remoto no autenticado provoque una condición de denegación de servicio (DoS) en un dispositivo afectado. Esta vulnerabilidad se debe a un desbordamiento de enteros durante el procesamiento del tráfico Modbus. Un… | |
| Analizada | Media (6.5) | 0.42% | — | Cisco Unified Threat Defense Snort Intrusion Prevention System Engine | 25/9/2024 | 17/6/2026 | Una vulnerabilidad en Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine para Cisco IOS XE Software podría permitir que un atacante remoto no autenticado omita las políticas de seguridad configuradas o provoque una condición de denegación de servicio (DoS) en un dispositivo afectado.… |