Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.19% | — | Beyondtrust Privileged Remote Access | 5/5/2025 | 17/6/2026 | BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions. | |
| Aplazada | Media (6.5) | 0.53% | — | Entrust Corp Printer ManagerAI | 25/4/2025 | 17/6/2026 | An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted POST request. | |
| Analizada | Alta (7.3) | 0.13% | — | Dell Trusted Device Agent | 15/4/2025 | 17/6/2026 | Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.3) | 0.18% | — | Dell Trusted Device Agent | 15/4/2025 | 17/6/2026 | Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Alta (7.5) | 0.92% | — | Trusty Plugins Shop Products FilterAI | 11/4/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Trusty Plugins Shop Products Filter trusty-woo-products-filter allows PHP Local File Inclusion.This issue affects Shop Products Filter: from n/a through <= 1.2. | |
| Aplazada | Media (4.7) | 0.35% | — | Rustaurius Ultimate WP MailAI | 9/4/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Phishing.This issue affects Ultimate WP Mail: from n/a through <= 1.3.10. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway | 3/4/2025 | 4/8/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution. | |
| Aplazada | Media (4.3) | 0.40% | — | Trust.reviews Fb-reviews-widgetAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in richplugins Trust.Reviews fb-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trust.Reviews: from n/a through <= 2.3. | |
| Aplazada | Media (4.9) | 0.62% | — | Rustaurius Five Star Restaurant ReservationsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.6.29. | |
| Aplazada | Crítica (9.3) | 0.61% | — | Trust Payments Gateway FOR WoocommerceAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trust Payments Trust Payments Gateway for WooCommerce trust-payments-hosted-payment-pages-integration allows SQL Injection.This issue affects Trust Payments Gateway for WooCommerce: from n/a through <= 1.1.4. | |
| Analizada | Media (4.8) | 0.29% | — | ARM Mbed TLSTrustedfirmware Mbed TLS | 25/3/2025 | 17/6/2026 | Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays. | |
| Analizada | Media (5.4) | 0.20% | — | ARM Mbed TLSTrustedfirmware Mbed TLS | 25/3/2025 | 17/6/2026 | Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname. | |
| Analizada | Alta (7.2) | 0.20% | — | Beyondtrust Privilege Management FOR Windows | 26/2/2025 | 17/6/2026 | Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process. | |
| Analizada | Alta (7.9) | 0.48% | — | Trustwave Modsecurity | 25/2/2025 | 17/6/2026 | Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in Libmodsecurity3 version 3.0.13 means that, in 3.0.13, Libmodsecurity3 can't decode… | |
| Aplazada | Media (6.3) | 0.68% | — | Rust-openssl OpensslAI | 3/2/2025 | 17/6/2026 | rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice pointing into the `server` argument's buffer but with a lifetime bound to the `client` argument. In situations where the `sever` buffer's lifetime is shorter than the `client`… | |
| Aplazada | Alta (7.1) | 0.26% | — | Trustist ReviewerAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trustist TRUSTist REVIEWer trustist-reviewer allows Reflected XSS.This issue affects TRUSTist REVIEWer: from n/a through <= 2.0. | |
| Analizada | Alta (7) | 17% | — | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 8/1/2025 | 17/6/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 8/1/2025 | 1/10/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution. | |
| Aplazada | Media (4.3) | 0.48% | — | Matrix-rust-sdk Matrix-sdk-cryptoAI | 7/1/2025 | 17/6/2026 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK… | |
| Analizada | Alta (7.2) | 14% | ⚠ Explotación activa | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 18/12/2024 | 17/6/2026 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. | |
| Analizada | Crítica (9.8) | 87% | ⚠ Explotación activa💥 Exploit | Beyondtrust Privileged Remote AccessBeyondtrust Remote Support | 17/12/2024 | 17/6/2026 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user. | |
| Analizada | Alta (7.5) | 0.73% | — | Rustls Project Rustls | 6/12/2024 | 17/6/2026 | A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message. | |
| Aplazada | Alta (8.1) | 0.34% | — | Confidential Computing Consortium TrusteeAI | 8/11/2024 | 17/6/2026 | Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by AS, could be manipulated by MITM attacker, but the verifier (CoCo Verification Demander like KBS) could still verify it successfully. In the payload of… | |
| Analizada | Media (6.1) | 0.22% | — | Beyondtrust Privileged Identity | 30/10/2024 | 17/6/2026 | A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks. | |
| Analizada | Crítica (9.8) | 0.63% | — | Trustedfirmware Mbed TLS | 15/10/2024 | 17/6/2026 | Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair |