Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

697 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.66%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom15/11/202317/6/2026
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
ModificadaMedia (6.5)0.85%—Zoom MeetingsZoom Video Software Development KITZoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaAlta (7.5)1.1%—Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom Virtual Desktop Infrastructure+114/11/202317/6/2026
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
ModificadaAlta (7.5)0.93%—Zoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
ModificadaMedia (5.5)0.21%—Zoom RoomsZoom Virtual Desktop Infrastructure14/11/202317/6/2026
Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.
ModificadaMedia (6.5)0.62%—Zoom MeetingsZoom RoomsZoom Virtual Desktop InfrastructureZoom14/11/202317/6/2026
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (6.5)1.1%—Zoom Meeting Software Development KITZoom Virtual Desktop InfrastructureZoom12/9/202317/6/2026
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
ModificadaMedia (5.4)0.44%—Cisco Application Policy Infrastructure Controller23/8/202317/6/2026
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated with a different security domain on an…
ModificadaMedia (6.1)0.46%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. The vulnerability is due to…
ModificadaMedia (5.4)0.45%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure16/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These…
ModificadaMedia (5.4)0.45%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure16/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These…
ModificadaMedia (5.4)0.44%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure16/8/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. These…
ModificadaCrítica (9.8)1.4%—Zoom Virtual Desktop InfrastructureZoom8/8/202317/6/2026
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.
ModificadaMedia (4.9)1.1%—Zoom RoomsZoom Virtual Desktop InfrastructureZoom8/8/202317/6/2026
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.
ModificadaMedia (6.5)1.2%—Zoom RoomsZoom Virtual Desktop InfrastructureZoom8/8/202317/6/2026
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.
ModificadaAlta (7.5)1.5%—Zoom RoomsZoom Virtual Desktop InfrastructureZoom8/8/202317/6/2026
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.
ModificadaMedia (5)0.14%—Fujitsu Software Infrastructure Manager7/8/202317/6/2026
An issue was discovered in Fujitsu Software Infrastructure Manager (ISM) before 2.8.0.061. The ismsnap component (in this specific case at /var/log/fujitsu/ServerViewSuite/ism/FirmwareManagement/FirmwareManagement.log) allows insecure collection and storage of authorization credentials in cleartext. That occurs when…
ModificadaAlta (7.5)0.42%—Fujitsu Software Infrastructure Manager4/8/202317/6/2026
Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager…
ModificadaBaja (3.7)0.50%—Jenkins Cloud Infrastructure Compute12/7/202317/6/2026
Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OCI clouds, enabling man-in-the-middle attacks.
ModificadaAlta (8.8)0.95%—Zoom RoomsZoomZoom Virtual Desktop Infrastructure13/6/202317/6/2026
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.
ModificadaAlta (7.8)0.13%—Zoom Virtual Desktop Infrastructure13/6/202317/6/2026
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to…
ModificadaAlta (7.1)0.16%—Zoom Virtual Desktop Infrastructure13/6/202317/6/2026
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
ModificadaAlta (7.8)0.70%—Dell Vxrail Hyperconverged Infrastructure23/5/202317/6/2026
Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable…