Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Cozmoslabs Client PortalAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in madalin.ungureanu Client Portal client-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Portal: from n/a through <= 1.2.1. | |
| Aplazada | Alta (8.6) | 0.68% | — | Ayukov Nftp ClientAI | 18/2/2026 | 17/6/2026 | Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST command with oversized payload to trigger a buffer overflow and execute a bind shell on port 5150. | |
| Analizada | Alta (8.8) | 0.39% | — | Bosch Rexroth IndraworksBosch Rexroth Ua.testclient | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user… | |
| Aplazada | Crítica (9.1) | 0.30% | — | Xiaomi Galaxy FDS SDK AndroidAIApache HttpclientAI | 12/2/2026 | 14/7/2026 | Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid… | |
| Aplazada | Alta (8.8) | 0.73% | — | Pacom Unison ClientAI | 11/2/2026 | 5/7/2026 | An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leading to Remote Code Execution. | |
| Analizada | Crítica (9.8) | 2.5% | 💥 PoC | Microsoft Azure Conversation Authoring Client Library | 10/2/2026 | 17/6/2026 | Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.1) | 0.23% | 💥 PoC | Fortinet Forticlient | 10/2/2026 | 17/6/2026 | An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with… | |
| Analizada | Crítica (9.9) | 0.52% | — | SAP Netweaver Application Server AbapSAP S/4hanaSAP Webclient UI Framework | 10/2/2026 | 17/6/2026 | An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on… | |
| Aplazada | Alta (8.4) | 0.75% | — | Cyberoam Authentication ClientAI | 7/2/2026 | 17/6/2026 | Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) memory. Attackers can craft a malicious input in the 'Cyberoam Server Address' field to trigger a bind TCP shell on port 1337 with… | |
| Analizada | Media (6.1) | 0.23% | — | Tgies Client-certificate-auth | 6/2/2026 | 17/6/2026 | client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulnerability. The middleware unconditionally redirects HTTP requests to HTTPS using the unvalidated Host header, allowing an… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | Fortinet Forticlientems | 6/2/2026 | 17/6/2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | |
| Aplazada | Alta (8.5) | 0.18% | — | Shrew Soft VPN ClientAI | 5/2/2026 | 17/6/2026 | Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot. | |
| Aplazada | Alta (8.5) | 0.18% | — | Ncp-e Secure Entry ClientAI | 5/2/2026 | 17/6/2026 | NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted paths in services like ncprwsnt, rwsrsu, ncpclcfg, and NcpSec to inject malicious code that would execute with… | |
| Analizada | Baja (2) | 0.12% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client | 4/2/2026 | 17/6/2026 | A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Aplazada | Media (5.1) | 0.12% | — | BR PVI ClientAI | 29/1/2026 | 17/6/2026 | An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local attacker to gather credential information which is processed by the PVI client application. The logging function of the PVI client application is disabled by default and… | |
| Analizada | Alta (7.5) | 0.30% | — | Bmeme Http Client Manager | 28/1/2026 | 17/6/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1. | |
| Aplazada | Alta (7.3) | 0.39% | 💥 PoC | Discord ClientAI | 23/1/2026 | 17/6/2026 | Discord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Discord Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Aplazada | Alta (7.5) | 0.08% | — | Harmony Sase Windows ClientAI | 14/1/2026 | 17/6/2026 | A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory. | |
| Analizada | Alta (7.5) | 0.93% | — | Microsoft Azure Core Shared Client Library | 13/1/2026 | 17/6/2026 | Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.2) | 7.8% | — | Fortinet Forticlientems | 13/1/2026 | 17/6/2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with… | |
| Aplazada | Media (6.4) | 0.25% | — | Client Testimonial SliderAI | 9/1/2026 | 17/6/2026 | The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aft_testimonial_meta_name' custom field in the Client Information metabox in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes… | |
| Aplazada | Alta (8.5) | 0.13% | — | Fujitsu Security Solution Authconductor Client BasicAI | 7/1/2026 | 17/6/2026 | Origin validation error issue exists in Fujitsu Security Solution AuthConductor Client Basic V2 2.0.25.0 and earlier. If this vulnerability is exploited, an attacker who can log in to the Windows system where the affected product is installed may execute arbitrary code with SYSTEM privilege and/or modify the registry… | |
| Aplazada | Alta (8.7) | 0.67% | — | Arteco WEB Client DVR NVRAI | 6/1/2026 | 17/6/2026 | Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization. | |
| Aplazada | Media (4.4) | 0.12% | — | Qnap Qfinder PRO MACAIQnap Qsync MACAIQnap Qvpn Device Client MACAI | 2/1/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and… | |
| Aplazada | Alta (7.1) | 0.42% | — | Fetch FTP ClientAI | 30/12/2025 | 17/6/2026 | Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the application. |