Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.11% | — | Versa-networks Sase Client | 20/12/2025 | 7/10/2026 | Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user.… | |
| Analizada | Alta (8.5) | 0.85% | — | Filezilla-project Filezilla Client | 19/12/2025 | 17/6/2026 | FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the… | |
| Analizada | Baja (2.1) | 0.35% | — | Lerouxyxchire Client Database Management System | 18/12/2025 | 17/6/2026 | A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the component Leads Generation Module. Executing manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Media (6.4) | 0.23% | — | Daggerhartlab Openid Connect Generic ClientAI | 18/12/2025 | 17/6/2026 | The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'openid_connect_generic_auth_url' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.18% | — | Boldgrid Sprout ClientsAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Reflected XSS.This issue affects Sprout Clients: from n/a through <= 3.2.1. | |
| Aplazada | Crítica (9.8) | 0.38% | — | Boldgrid Client Invoicing BY Sprout InvoicesAI | 18/12/2025 | 5/10/2026 | Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7. | |
| Aplazada | Media (6) | 0.12% | — | Amazon S3 Encryption Client FOR JavaAI | 17/12/2025 | 17/6/2026 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue,… | |
| Aplazada | Media (6) | 0.11% | — | Amazon S3 Encryption Client FOR GOAI | 17/12/2025 | 30/9/2026 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade… | |
| Aplazada | Media (6) | 0.11% | — | Amazon S3 Encryption Client FOR .netAI | 17/12/2025 | 17/6/2026 | Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue,… | |
| Analizada | Media (6.7) | 0.22% | — | Eyemaxsystems Nvclient | 15/12/2025 | 17/6/2026 | NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attackers to crash the application. Attackers can overwrite 846 bytes of memory by pasting a crafted payload into the contact box, causing a denial of service condition. | |
| Analizada | Media (5) | 0.21% | — | Jenkins GIT Client | 10/12/2025 | 17/6/2026 | Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands. | |
| Aplazada | Alta (8.5) | 0.12% | — | Lenovo Baiying ClientAI | 10/12/2025 | 17/6/2026 | An improper permissions vulnerability was reported in Lenovo Baiying Client that could allow a local authenticated user to execute code with elevated privileges. | |
| Aplazada | Alta (8.5) | 0.14% | — | Lenovo ONE ClientAI | 10/12/2025 | 25/9/2026 | A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges. | |
| Aplazada | Alta (8.7) | 0.49% | — | Commax UMS ClientAI | 9/12/2025 | 17/6/2026 | COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit improper boundary validation in CNC_Ctrl.dll to cause heap corruption and… | |
| Aplazada | Media (6.3) | 0.27% | 💥 PoC | Watchguard Mobile VPN With SSL ClientAI | 4/12/2025 | 25/9/2026 | The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed. | |
| Aplazada | Media (5.9) | 0.13% | — | Netskope NS ClientAI | 28/11/2025 | 17/6/2026 | Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, a local, authenticated user with Administrator privileges can improperly load the driver as a generic kernel service. This triggers the flaw, causing a system crash (Blue-Screen-of-Death) and… | |
| Analizada | Crítica (9.8) | 0.57% | — | Ncp-e NCP Secure Entry ClientNcp-e Secure Enterprise Client | 26/11/2025 | 17/6/2026 | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability. | |
| Aplazada | Alta (8.8) | 0.37% | — | Fail2ban-clientAI | 26/11/2025 | 17/6/2026 | Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root. NOTE: this is disputed by multiple parties because the action for a triggered rule can legitimately be an arbitrary operation as root. Thus, the software is behaving in accordance with… | |
| Analizada | Media (5.5) | 0.15% | — | Fortinet Forticlient | 18/11/2025 | 17/6/2026 | An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password | |
| Modificada | Alta (7.8) | 0.16% | — | Fortinet Forticlient | 18/11/2025 | 17/6/2026 | An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the… | |
| Modificada | Alta (7.8) | 0.15% | — | Fortinet Forticlient | 18/11/2025 | 17/6/2026 | A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips_74.sys". The attacker would need to bypass the Windows heap… | |
| Aplazada | Media (5.2) | 0.12% | — | Zscaler Client ConnectorAI | 12/11/2025 | 17/6/2026 | A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls. | |
| Aplazada | Media (6.9) | 0.16% | — | SAP Hana Jdbc ClientAI | 11/11/2025 | 17/6/2026 | Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application. | |
| Analizada | Alta (7.1) | 0.20% | — | Lerouxyxchire Client Database Management System | 10/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_delete.php) accepts POST… | |
| Aplazada | Alta (8.8) | 0.20% | — | Amazon Workspaces Client LinuxAI | 5/11/2025 | 17/6/2026 | Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, a local user may be able to extract another local user's… |