Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.52% | — | Gsheetconnector CF7 Google Sheets ConnectorAI | 26/3/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5. | |
| Analizada | Alta (7.8) | 0.27% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later. | |
| Analizada | Alta (7.8) | 0.31% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later. | |
| Analizada | Alta (7.8) | 0.24% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later. | |
| Analizada | Alta (7.1) | 0.31% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later. | |
| Analizada | Alta (7.8) | 0.25% | — | Snowflake Hive Metastore Connector | 15/3/2024 | 17/6/2026 | The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaStore Connector. A malicious insider without admin privileges could, in theory,… | |
| Analizada | Alta (7.5) | 0.51% | — | Softing EdgeaggregatorSofting Edgeconnector | 14/3/2024 | 17/6/2026 | The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests. | |
| Modificada | Media (5.3) | 0.43% | — | Gsheetconnector Woocommerce Google Sheet Connector | 21/2/2024 | 17/6/2026 | The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings. | |
| Modificada | Alta (7.4) | 0.54% | — | SAP Cloud Connector | 13/2/2024 | 17/6/2026 | Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system. | |
| Modificada | Alta (8.8) | 0.21% | — | Ari-soft Contact Form 7 Connector | 12/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.2.2. | |
| Modificada | Alta (7) | 0.31% | — | Forescout Secureconnector | 8/2/2024 | 17/6/2026 | Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component. | |
| Modificada | Media (6.5) | 0.36% | — | Elastic Network Drive Connector | 7/2/2024 | 17/6/2026 | An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user. | |
| Modificada | Media (6.1) | 0.45% | — | Ari-soft Contact Form 7 Connector | 16/1/2024 | 17/6/2026 | The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators. | |
| Modificada | Alta (7.5) | 0.52% | — | SAP GUI Connector | 9/1/2024 | 17/6/2026 | Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access highly sensitive information which would otherwise be restricted causing high impact on confidentiality. | |
| Modificada | Alta (7.5) | 0.35% | — | Snowflake Connector | 22/12/2023 | 17/6/2026 | The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the… | |
| Modificada | Baja (3.5) | 0.27% | — | SAP Cloud Connector | 12/12/2023 | 17/6/2026 | SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no impact on confidentiality or Integrity of the application. | |
| Modificada | Alta (7.8) | 0.26% | — | Autodesk Desktop Connector | 22/11/2023 | 17/6/2026 | A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability. | |
| Modificada | Media (5.4) | 0.23% | — | Zscaler Client Connector | 21/11/2023 | 17/6/2026 | An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler Diagnostics. This issue affects Client Connector: before 4.2.0.149. | |
| Modificada | Media (6.5) | 0.20% | — | Zscaler Client Connector | 6/11/2023 | 17/6/2026 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.18% | — | Sonicwall Directory Services Connector | 27/10/2023 | 17/6/2026 | A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature. | |
| Modificada | Media (6.5) | 0.36% | — | Elastic Sharepoint Online Python Connector | 26/10/2023 | 17/6/2026 | An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through… | |
| Modificada | Crítica (9.8) | 0.35% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105 | |
| Modificada | Media (5.3) | 0.24% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105 | |
| Modificada | Media (6.5) | 0.26% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affects Client Connector: before 3.9. | |
| Modificada | Alta (7.3) | 0.22% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user. |