Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1437 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.27% | — | Arubanetworks Clearpass Policy Manager | 3/12/2024 | 17/6/2026 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including… | |
| Analizada | Alta (8) | 0.46% | — | Arubanetworks Clearpass Policy Manager | 3/12/2024 | 17/6/2026 | An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Analizada | Alta (8.8) | 0.76% | — | Arubanetworks Clearpass Policy Manager | 3/12/2024 | 17/6/2026 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system. | |
| Analizada | Crítica (9.1) | 1.7% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.1) | 1.7% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.1) | 1.9% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.8) | 0.30% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges. | |
| Analizada | Crítica (9.1) | 1.7% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.6% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.6% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Media (6.1) | 0.85% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required. | |
| Modificada | Alta (8.8) | 1.4% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution | |
| Analizada | Alta (7.5) | 1.4% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Media (4.9) | 1.1% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service. | |
| Analizada | Alta (7.8) | 0.22% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges. | |
| Analizada | Media (4.9) | 1.1% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service. | |
| Modificada | Alta (7.2) | 1.6% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (8.8) | 71% | 💥 Exploit | Ivanti Connect SecureIvanti Policy Secure | 18/10/2024 | 17/6/2026 | Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution. | |
| Analizada | Alta (8.6) | 11% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 16/10/2024 | 17/6/2026 | BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.3) | 0.34% | — | Openpolicyagent Open Policy Agent | 30/8/2024 | 17/6/2026 | A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. | |
| Analizada | Alta (7.2) | 0.74% | — | Cisco Application Policy Infrastructure Controller | 28/8/2024 | 17/6/2026 | A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges to install a modified software image, leading to arbitrary… | |
| Analizada | Media (4.3) | 0.32% | — | Cisco Application Policy Infrastructure Controller | 28/8/2024 | 17/6/2026 | A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system. This vulnerability is due… | |
| Analizada | Alta (8.7) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.3) | 0.30% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |