Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

404 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.76%—Bitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet SecurityBitdefender Total Security7/3/202217/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a remote attacker to escalate local privileges to SYSTEM. This issue affects: Bitdefender…
ModificadaMedia (6.1)0.55%—Bitdefender Antivirus PlusBitdefender Endpoint Security ToolsBitdefender Internet SecurityBitdefender Total Security+17/3/202217/6/2026
A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product processes and generate crashdump files. This issue affects: Bitdefender Total…
ModificadaAlta (7.8)0.32%—Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security18/2/202217/6/2026
A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136.…
ModificadaMedia (5.3)0.89%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1025/1/202217/6/2026
On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters on the Hypervisor) and TCP Segmentation Offload…
ModificadaMedia (5.3)0.73%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1025/1/202217/6/2026
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of…
ModificadaMedia (5.3)0.92%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1025/1/202217/6/2026
On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new…
ModificadaAlta (7.5)0.90%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1025/1/202217/6/2026
On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical…
ModificadaMedia (6.5)0.90%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1125/1/202217/6/2026
On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory resource utilization. Note: Software versions which have…
ModificadaAlta (7.8)0.31%—Bitdefender Gravityzone16/12/202117/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects Bitdefender GravityZone versions prior to 3.3.8.272
ModificadaAlta (7.5)1.7%—Bitdefender Gravityzone16/12/202117/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Bitdefender GravityZone versions prior to 3.3.8.272
ModificadaAlta (7.2)2.2%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Remote Code Execution Vulnerability
ModificadaAlta (7.5)3.0%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Information Disclosure Vulnerability
ModificadaCrítica (9.8)2.4%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Remote Code Execution Vulnerability
ModificadaAlta (8.8)2.2%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Remote Code Execution Vulnerability
ModificadaAlta (8.8)2.2%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Remote Code Execution Vulnerability
ModificadaCrítica (9.8)3.8%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.54%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Elevation of Privilege Vulnerability
ModificadaCrítica (9.8)4.2%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Remote Code Execution Vulnerability
ModificadaCrítica (9.8)2.0%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Remote Code Execution Vulnerability
ModificadaAlta (8.8)2.7%—Microsoft Defender FOR IOT15/12/202117/6/2026
Microsoft Defender for IoT Remote Code Execution Vulnerability
ModificadaCrítica (10)2.1%—Bitdefender Endpoint Security ToolsBitdefender Gravityzone24/11/202117/6/2026
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390;…
ModificadaAlta (7.5)1.3%—Bitdefender Endpoint Security ToolsBitdefender Gravityzone24/11/202117/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows an attacker to use the Endpoint Protection relay as a proxy for any remote host. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33.…
ModificadaAlta (7.5)1.3%—Bitdefender Endpoint Security ToolsBitdefender Gravityzone24/11/202117/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Endpoint Security Tools versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender GravityZone…
AnalizadaAlta (7.5)25%💥 PoCBalasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+2611/11/202123/9/2026
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network…
ModificadaMedia (6.1)0.35%—Bitdefender Gravityzone9/11/202117/6/2026
Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows allows a local attacker to cause a denial of service. This issue affects: Bitdefender GravityZone version 7.1.2.33 and prior versions.
Orbitaley — Vulnerabilidades