Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

571 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.52%—Gsheetconnector CF7 Google Sheets ConnectorAI26/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5.
AnalizadaAlta (7.8)0.27%—Zscaler Client Connector26/3/202417/6/2026
The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later.
AnalizadaAlta (7.8)0.31%—Zscaler Client Connector26/3/202417/6/2026
ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later.
AnalizadaAlta (7.8)0.24%—Zscaler Client Connector26/3/202417/6/2026
In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.
AnalizadaAlta (7.1)0.31%—Zscaler Client Connector26/3/202417/6/2026
An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later.
AnalizadaAlta (7.8)0.25%—Snowflake Hive Metastore Connector15/3/202417/6/2026
The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaStore Connector. A malicious insider without admin privileges could, in theory,…
AnalizadaAlta (7.5)0.51%—Softing EdgeaggregatorSofting Edgeconnector14/3/202417/6/2026
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.
ModificadaMedia (5.3)0.43%—Gsheetconnector Woocommerce Google Sheet Connector21/2/202417/6/2026
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.
ModificadaAlta (7.4)0.54%—SAP Cloud Connector13/2/202417/6/2026
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system.
ModificadaAlta (8.8)0.21%—Ari-soft Contact Form 7 Connector12/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.2.2.
ModificadaAlta (7)0.31%—Forescout Secureconnector8/2/202417/6/2026
Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.
ModificadaMedia (6.5)0.36%—Elastic Network Drive Connector7/2/202417/6/2026
An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Drive it is visible in search applications to the user.
ModificadaMedia (6.1)0.45%—Ari-soft Contact Form 7 Connector16/1/202417/6/2026
The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.
ModificadaAlta (7.5)0.52%—SAP GUI Connector9/1/202417/6/2026
Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access highly sensitive information which would otherwise be restricted causing high impact on confidentiality.
ModificadaAlta (7.5)0.35%—Snowflake Connector22/12/202317/6/2026
The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the…
ModificadaBaja (3.5)0.27%—SAP Cloud Connector12/12/202317/6/2026
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no impact on confidentiality or Integrity of the application.
ModificadaAlta (7.8)0.26%—Autodesk Desktop Connector22/11/202317/6/2026
A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability.
ModificadaMedia (5.4)0.23%—Zscaler Client Connector21/11/202317/6/2026
An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler Diagnostics. This issue affects Client Connector: before 4.2.0.149.
ModificadaMedia (6.5)0.20%—Zscaler Client Connector6/11/202317/6/2026
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
ModificadaAlta (7.8)0.18%—Sonicwall Directory Services Connector27/10/202317/6/2026
A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature.
ModificadaMedia (6.5)0.36%—Elastic Sharepoint Online Python Connector26/10/202317/6/2026
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through…
ModificadaCrítica (9.8)0.35%—Zscaler Client Connector23/10/202317/6/2026
An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105
ModificadaMedia (5.3)0.24%—Zscaler Client Connector23/10/202317/6/2026
An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105
ModificadaMedia (6.5)0.26%—Zscaler Client Connector23/10/202317/6/2026
An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affects Client Connector: before 3.9.
ModificadaAlta (7.3)0.22%—Zscaler Client Connector23/10/202317/6/2026
Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user.