Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.20% | — | Zscaler Client Connector | 6/11/2023 | 17/6/2026 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Media (6.5) | 0.45% | — | Dell Powerscale Onefs | 2/11/2023 | 17/6/2026 | Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure. | |
| Modificada | Media (6.5) | 0.62% | — | Dell Powerscale Onefs | 2/11/2023 | 17/6/2026 | Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition. | |
| Modificada | Alta (7.5) | 0.89% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/10/2023 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server | |
| Modificada | Crítica (9.8) | 0.35% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105 | |
| Modificada | Media (5.3) | 0.24% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105 | |
| Modificada | Media (6.5) | 0.26% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affects Client Connector: before 3.9. | |
| Modificada | Alta (7.3) | 0.22% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user. | |
| Modificada | Alta (7.8) | 0.18% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.15% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.30% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.23% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges. | |
| Modificada | Media (4.7) | 0.11% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition. | |
| Modificada | Alta (7.8) | 0.22% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges. | |
| Modificada | Alta (7.8) | 0.13% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges. | |
| Modificada | Media (5.5) | 0.14% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context. | |
| Modificada | Alta (7.5) | 0.64% | — | Wipotec Comscale | 18/10/2023 | 17/6/2026 | WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underlying operating system and obtain directory listings. | |
| Modificada | Crítica (9.8) | 0.82% | — | Wipotec Comscale | 18/10/2023 | 17/6/2026 | An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/10/2023 | 31/7/2026 | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (5.5) | 0.38% | 💥 PoC | Zscaler Proxy | 31/8/2023 | 17/6/2026 | Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload restrictions. | |
| Modificada | Crítica (9.8) | 0.39% | — | Zscaler Internet Access Admin Portal | 31/8/2023 | 17/6/2026 | An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r. | |
| Modificada | Alta (8.8) | 0.63% | — | Dell Powerscale Onefs | 29/8/2023 | 17/6/2026 | Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Modificada | Alta (7.8) | 0.18% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Modificada | Crítica (9.8) | 0.78% | — | Dell Powerscale Onefs | 16/8/2023 | 17/6/2026 | Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution. |