Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.3)0.19%—Beyondtrust Privileged Remote Access5/5/202517/6/2026
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.
AplazadaMedia (6.5)0.53%—Entrust Corp Printer ManagerAI25/4/202517/6/2026
An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted POST request.
AnalizadaAlta (7.3)0.13%—Dell Trusted Device Agent15/4/202517/6/2026
Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.3)0.18%—Dell Trusted Device Agent15/4/202517/6/2026
Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AplazadaAlta (7.5)0.92%—Trusty Plugins Shop Products FilterAI11/4/202517/6/2026
Path Traversal: '.../...//' vulnerability in Trusty Plugins Shop Products Filter trusty-woo-products-filter allows PHP Local File Inclusion.This issue affects Shop Products Filter: from n/a through <= 1.2.
AplazadaMedia (4.7)0.35%—Rustaurius Ultimate WP MailAI9/4/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Phishing.This issue affects Ultimate WP Mail: from n/a through <= 1.3.10.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway3/4/20254/8/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
AplazadaMedia (4.3)0.40%—Trust.reviews Fb-reviews-widgetAI27/3/202517/6/2026
Missing Authorization vulnerability in richplugins Trust.Reviews fb-reviews-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trust.Reviews: from n/a through <= 2.3.
AplazadaMedia (4.9)0.62%—Rustaurius Five Star Restaurant ReservationsAI27/3/202517/6/2026
Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.6.29.
AplazadaCrítica (9.3)0.61%—Trust Payments Gateway FOR WoocommerceAI26/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trust Payments Trust Payments Gateway for WooCommerce trust-payments-hosted-payment-pages-integration allows SQL Injection.This issue affects Trust Payments Gateway for WooCommerce: from n/a through <= 1.1.4.
AnalizadaMedia (4.8)0.29%—ARM Mbed TLSTrustedfirmware Mbed TLS25/3/202517/6/2026
Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication bypasses such as replays.
AnalizadaMedia (5.4)0.20%—ARM Mbed TLSTrustedfirmware Mbed TLS25/3/202517/6/2026
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname.
AnalizadaAlta (7.2)0.20%—Beyondtrust Privilege Management FOR Windows26/2/202517/6/2026
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.
AnalizadaAlta (7.9)0.48%—Trustwave Modsecurity25/2/202517/6/2026
Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. A bug that exists only in Libmodsecurity3 version 3.0.13 means that, in 3.0.13, Libmodsecurity3 can't decode…
AplazadaMedia (6.3)0.68%—Rust-openssl OpensslAI3/2/202517/6/2026
rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice pointing into the `server` argument's buffer but with a lifetime bound to the `client` argument. In situations where the `sever` buffer's lifetime is shorter than the `client`…
AplazadaAlta (7.1)0.26%—Trustist ReviewerAI13/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trustist TRUSTist REVIEWer trustist-reviewer allows Reflected XSS.This issue affects TRUSTist REVIEWer: from n/a through <= 2.0.
AnalizadaAlta (7)17%—Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure8/1/202517/6/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure8/1/20251/10/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
AplazadaMedia (4.3)0.48%—Matrix-rust-sdk Matrix-sdk-cryptoAI7/1/202517/6/2026
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK…
AnalizadaAlta (7.2)14%⚠ Explotación activaBeyondtrust Privileged Remote AccessBeyondtrust Remote Support18/12/202417/6/2026
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
AnalizadaCrítica (9.8)87%⚠ Explotación activa💥 ExploitBeyondtrust Privileged Remote AccessBeyondtrust Remote Support17/12/202417/6/2026
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
AnalizadaAlta (7.5)0.73%—Rustls Project Rustls6/12/202417/6/2026
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
AplazadaAlta (8.1)0.34%—Confidential Computing Consortium TrusteeAI8/11/202417/6/2026
Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by AS, could be manipulated by MITM attacker, but the verifier (CoCo Verification Demander like KBS) could still verify it successfully. In the payload of…
AnalizadaMedia (6.1)0.22%—Beyondtrust Privileged Identity30/10/202417/6/2026
A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.
AnalizadaCrítica (9.8)0.63%—Trustedfirmware Mbed TLS15/10/202417/6/2026
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
Orbitaley — Vulnerabilidades