Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1829 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.13% | — | Acronis Cyber Protect | 6/3/2026 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. | |
| Analizada | Crítica (9.8) | 0.63% | — | Acronis Cyber Protect | 6/3/2026 | 17/6/2026 | Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | |
| Analizada | Media (4.3) | 0.27% | — | Acronis Cyber Protect | 6/3/2026 | 17/6/2026 | Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | |
| Analizada | Media (4.4) | 0.16% | — | Acronis AgentAcronis Cyber Protect | 6/3/2026 | 17/6/2026 | Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | |
| Analizada | Alta (7.1) | 0.10% | — | Acronis AgentAcronis Cyber Protect | 6/3/2026 | 17/6/2026 | Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124. | |
| Aplazada | Alta (8.5) | 0.39% | — | Wpchill Filr ProtectionAI | 5/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14. | |
| Aplazada | Media (6.4) | 0.20% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 25/2/2026 | 17/6/2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ays_block' shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Crítica (10) | 0.46% | — | Acronis Cyber Protect | 20/2/2026 | 17/6/2026 | Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. | |
| Analizada | Crítica (10) | 0.71% | — | Acronis Cyber Protect | 20/2/2026 | 17/6/2026 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. | |
| Analizada | Crítica (10) | 0.80% | — | Acronis Cyber Protect | 20/2/2026 | 17/6/2026 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 16AIAcronis Cyber Protect 15AI | 20/2/2026 | 17/6/2026 | Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build… | |
| Analizada | Media (6.5) | 0.20% | — | Dell Powerprotect Data Manager | 19/2/2026 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service of a Dell Enterprise Support connection. | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Powerprotect Data Manager | 19/2/2026 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.8) | 0.29% | — | Dell Powerprotect Data Manager | 19/2/2026 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. | |
| Aplazada | Media (4.3) | 0.28% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Secure Copy Content Protection and Content Locking: from n/a through <= 5.0.0. | |
| Analizada | Media (4.7) | 0.18% | — | Dell Powerprotect Data Manager | 19/2/2026 | 17/6/2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. | |
| Aplazada | Media (5.3) | 0.27% | — | Stickease Protected Contact FormAI | 14/2/2026 | 17/6/2026 | The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.0.2. The plugin stores spam detection logs at a predictable publicly accessible location (wp-content/uploads/stickeasy-protected-contact-form/spcf-log.txt). This makes it… | |
| Aplazada | Alta (7.2) | 0.27% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 12/2/2026 | 17/6/2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (6.9) | 0.60% | — | Crystal Shard Http-protectionAI | 30/1/2026 | 17/6/2026 | Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized… | |
| Aplazada | Media (4.4) | 0.15% | — | Symantec Endpoint ProtectionAI | 28/1/2026 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry. | |
| Aplazada | Media (6.7) | 0.17% | — | Symantec Endpoint ProtectionAI | 28/1/2026 | 17/6/2026 | Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an… | |
| Analizada | Media (6.5) | 0.32% | — | Dell Data Protection Advisor | 23/1/2026 | 17/6/2026 | Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.5) | 0.43% | — | UI Unifi Protect | 5/1/2026 | 17/6/2026 | A malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery protocol causing it to restart. Affected Products: UniFi Protect Application (Version 6.1.79 and earlier). Mitigation: Update your UniFi Protect Application to Version 6.2.72 or… | |
| Analizada | Alta (8.8) | 0.46% | — | UI Unifi Protect | 5/1/2026 | 17/6/2026 | A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerability in the Unifi Protect Application (Version 6.1.79 and earlier). Affected Products: UniFi Protect Application (Version 6.1.79 and earlier). Mitigation: Update… |