Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1881 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.21%—HP Client Management Script Library3/11/202517/6/2026
A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. HP is releasing software updates to mitigate the potential vulnerability.
AplazadaMedia (4.3)0.19%—Webventures Client Invoicing BY Sprout InvoicesAI29/10/202517/6/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
AnalizadaBaja (2.1)0.46%—Fabian Client Details System27/10/202517/6/2026
A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
AnalizadaBaja (1.9)0.29%—Fabian Client Details System27/10/202517/6/2026
A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function of the file /admin/manage-users.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used.
AnalizadaBaja (1.9)0.25%—Fabian Client Details System27/10/202517/6/2026
A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaBaja (1.9)0.25%—Fabian Client Details System27/10/202517/6/2026
A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
AnalizadaBaja (1.9)0.26%—Fabian Client Details System27/10/202530/9/2026
A vulnerability has been found in code-projects Client Details System 1.0. This vulnerability affects unknown code of the file /welcome.php. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
AnalizadaBaja (2.1)0.38%—Fabian Client Details System27/10/202517/6/2026
A vulnerability was found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the file clientdetails/welcome.php of the component GET Parameter Handler. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit…
AnalizadaMedia (6.1)0.30%—Hcltech Bigfix MobileHcltech Bigfix Modern Client Management16/10/202517/6/2026
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
AnalizadaMedia (6.1)0.30%—Hcltech Bigfix MobileHcltech Bigfix Modern Client Management16/10/202517/6/2026
HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
AnalizadaMedia (4.3)0.26%—Hcltech Bigfix MobileHcltech Bigfix Modern Client Management16/10/202517/6/2026
HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
AnalizadaMedia (4.3)0.26%—Hcltech Bigfix MobileHcltech Bigfix Modern Client Management16/10/202517/6/2026
HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
AplazadaBaja (2.3)0.09%—Lenovo Universal Device ClientAI15/10/202517/6/2026
An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.
AnalizadaAlta (8.8)0.60%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1414/10/202517/6/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.13%—Fortinet Forticlient14/10/202517/6/2026
An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking.
AnalizadaAlta (7.3)0.18%—Fortinet Forticlient14/10/202517/6/2026
An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.
AnalizadaAlta (7.8)0.08%—Fortinet Forticlient14/10/202517/6/2026
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow a local user to escalate their privileges via FortiClient related executables.
AnalizadaAlta (7.1)0.28%—Fortinet Forticlient14/10/202517/6/2026
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious website.
AnalizadaBaja (2.1)0.36%—Fabian Client Details System11/10/202517/6/2026
A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/update-profile.php. Such manipulation of the argument uid leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
ModificadaMedia (6.1)0.23%—Fabian Client Details System9/10/20255/7/2026
code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code in the username field.
AplazadaCrítica (9.3)0.21%—Amazon VPN ClientAI7/10/202517/6/2026
Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient validation checks on the log destination directory during log rotation could allow a non-administrator user to create a symlink from a client log…
AplazadaMedia (5.3)0.22%—Conventional-changelog Git-clientAI22/9/202517/6/2026
Conventional Changelog generates changelogs and release notes from a project's commit messages and metadata. Prior to version 2.0.0, @conventional-changelog/git-client has an argument injection vulnerability. This vulnerability manifests with the library's getTags() API, which allows extra parameters to be passed to…
AplazadaBaja (3.7)0.21%—Purevpn ClientAI18/9/202517/6/2026
PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. This removes firewall rules that may have been configured manually or by other software (e.g., UFW, container engines, or…
AplazadaMedia (6.8)0.31%—Kubernetes C ClientAI16/9/202517/6/2026
A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a malicious actor to present a forged certificate and potentially intercept or manipulate…
AplazadaAlta (7.5)0.19%—Lenovo Wallpaper ClientAI11/9/202517/6/2026
A potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under certain conditions.