Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
5089 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.36% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 1/4/2026 | 17/6/2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow an unauthenticated user to execute arbitrary commands as lower user privileges on… | |
| Analizada | Baja (3.8) | 0.41% | — | Sonicwall Email Security | 31/3/2026 | 24/7/2026 | A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database. | |
| Analizada | Baja (2.7) | 0.47% | — | Sonicwall Email Security | 31/3/2026 | 24/7/2026 | A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive. | |
| Analizada | Media (4.8) | 0.29% | — | Sonicwall Email Security | 31/3/2026 | 24/7/2026 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code. | |
| Analizada | Media (6.5) | 0.40% | — | Opensecurity Mobile Security Framework | 26/3/2026 | 17/6/2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 542-566) uses Python string formatting (`%`) to construct SQL queries with table names read from a SQLite database's `sqlite_master` table. When a security analyst uses… | |
| Analizada | Alta (8.6) | 0.35% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE | 25/3/2026 | 17/9/2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak,… | |
| Analizada | Media (4.6) | 0.48% | — | Stepsecurity Harden-runner | 20/3/2026 | 17/6/2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows attackers to bypass egress-policy: block network restrictions by tunneling exfiltrated data through permitted HTTPS endpoints like dns.google. The attack… | |
| Analizada | Media (4.6) | 0.39% | — | Stepsecurity Harden-runner | 20/3/2026 | 17/6/2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, the Harden-Runner that allows bypass of the egress-policy: block network restriction using DNS queries over TCP. Egress policies are enforced on GitHub runners by filtering outbound connections at… | |
| Analizada | Crítica (9.1) | 0.48% | 💥 PoC | Vmware Spring Security | 19/3/2026 | 17/6/2026 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through… | |
| Aplazada | Media (6.5) | 0.36% | — | Really-simple-plugins Really Simple Security PROAI | 19/3/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple Security Pro: from n/a through 9.5.4.0. | |
| Analizada | Media (5.4) | 0.14% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.5) | 0.10% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user. | |
| Analizada | Media (5.4) | 0.14% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality. | |
| Analizada | Media (5) | 0.18% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account. | |
| Analizada | Crítica (9.3) | 0.80% | — | Dragonsoft Gcb/fcb Government Financial Cybersecurity Configuration Audit Software | 17/3/2026 | 17/6/2026 | GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account. | |
| Analizada | Media (4.8) | 0.16% | — | Forcepoint WEB Security | 16/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web Security through 8.5.6. | |
| Analizada | Alta (8.2) | 0.17% | — | Simplesamlphp Xml-security | 16/3/2026 | 17/6/2026 | xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key,… | |
| Aplazada | Media (5.1) | 0.26% | — | Zkteco Zkaccess Security SystemAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the 'holiday_name' and 'memo' POST parameters. Attackers can submit crafted requests with script code in these parameters to… | |
| Aplazada | Media (6.8) | 0.15% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClientIp() method which treats IPv6 loopback address 0:0:0:0:0:0:0:1 as 127.0.0.1 and… | |
| Aplazada | Crítica (9.3) | 0.56% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user… | |
| Aplazada | Media (6.9) | 0.21% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source… | |
| Aplazada | Media (5.3) | 0.21% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Attackers can craft HTTP requests that add superadmin accounts without validity checks, enabling unauthorized administrative… | |
| Aplazada | Media (5.1) | 0.25% | — | Zkteco ZkbiosecurityAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script code by injecting malicious payloads through unsanitized parameters in multiple scripts. Attackers can craft malicious URLs with XSS payloads in vulnerable parameters to… | |
| Aplazada | Crítica (9.3) | 0.78% | — | Zkteco ZkbiosecurityAIApache TomcatAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute… | |
| Analizada | Media (5.3) | 0.28% | — | Siemens Sinec Security Monitor | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`. |